CVE-2026-23918 is a double-free memory corruption vulnerability within the Apache HTTP Server's HTTP/2 module (mod_http2)
VMware Aria Operations 8.18.6
VMware By Broadcom is aware of CVE-2026-23918.
Refer to the release notes for existing and forthcoming product releases for any updates in relation to this CVE.
Should you require further information contact Broadcom Support