CVE-2026-63686
Received Received - Intake

NULL Pointer Dereference in Apache HTTP Server

Vulnerability report for CVE-2026-63686, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Apache Software Foundation

Description

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache_software_foundation apache_http_server 2.4.69

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in mod_xml2enc, a module in Apache HTTP Server. It occurs when a backend server sends a proxied response with a charset conversion that partially succeeds but then fails. This causes the server to dereference a NULL pointer, leading to a denial of service.

Detection Guidance

This vulnerability can be detected by checking the Apache HTTP Server version. Run 'apache2 -v' or 'httpd -v' on Unix-like systems to verify if the version is below 2.4.69. If the server is vulnerable, upgrade to version 2.4.69 or later.

Impact Analysis

This vulnerability can cause your Apache HTTP Server to crash or become unresponsive, resulting in a denial of service. If you rely on this server for web services, it could disrupt access to your websites or applications.

Compliance Impact

This vulnerability causes a denial of service via a NULL pointer dereference in mod_xml2enc, which could disrupt services handling sensitive data. However, there is no direct evidence in the provided context that this vulnerability specifically impacts compliance with GDPR, HIPAA, or similar regulations.

Mitigation Strategies

Immediately upgrade Apache HTTP Server to version 2.4.69 or later. This fixes the NULL pointer dereference issue in mod_xml2enc. No other immediate steps are specified in the provided context.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63686. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart