PT-2026-36812 · Apache+2 · Apache Http Server+2
Pavel Kohout
·
Published
2026-03-04
·
Updated
2026-05-22
·
CVE-2026-29169
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.66
Description
A NULL pointer dereference in the
mod dav lock module may allow an attacker to crash the server by sending a malicious request. A NULL pointer dereference occurs when a program attempts to read or write to a memory address that is NULL, typically leading to an application crash.Recommendations
Upgrade to version 2.4.66.
Remove the
mod dav lock module.Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Linuxmint
Ubuntu