#Debian stable #apache2 package 2.4.66-1~deb13u2 already includes the fix for CVE-2026-23918.
You an verify this by apt-get source apache2 and then checking out apache2-2.4.66/debian/patches/bug1125368.patch
The security tracker at https://security-tracker.debian.org/tracker/CVE-2026-23918 currently has wrong information. This is likely due to automation based on version numbers alone.








