NULL Pointer Dereference Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-63686
Currently unrated
What is CVE-2026-63686?
A vulnerability exists in Apache HTTP Server that causes a NULL pointer dereference in the mod_xml2enc module. This issue can be exploited by an untrusted backend server, potentially leading to a denial of service condition due to an improperly handled charset conversion in proxied responses. Users are strongly advised to upgrade to version 2.4.69 or higher to mitigate this risk.
Affected Version(s)
Apache HTTP Server 2.4.0 <= 2.4.68