5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Description
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Basic Information
ID
CVE-2026-33007
Source
apache
Published
May 4, 2026 at 14:41
Modified
May 4, 2026 at 15:13
Affected Product
Vendor
Apache Software Foundation
Product
Apache HTTP Server
Version
2.4.0
Affected Versions
Apache Software Foundation Apache HTTP Server 2.4.0