NULL Pointer Dereference Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-63686

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-63686?

A vulnerability exists in Apache HTTP Server that causes a NULL pointer dereference in the mod_xml2enc module. This issue can be exploited by an untrusted backend server, potentially leading to a denial of service condition due to an improperly handled charset conversion in proxied responses. Users are strongly advised to upgrade to version 2.4.69 or higher to mitigate this risk.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucian Nitescu
Zhen Kong
.