Description
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.



This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A NULL pointer dereference has been discovered in the mod_heartmonitor module of Apache HTTP Server. The flaw is triggered when the unicast listener processes malformed or crafted traffic, causing the server process to crash and become unavailable. The impact is a denial of service that can affect the entire HTTP service without providing any other system compromise.

Affected Systems

Apache HTTP Server versions from 2.4.0 to 2.4.68, inclusive, are impacted. The vulnerability exists in the core mod_heartmonitor module used by these releases.

Risk and Exploitability

The CVSS score is not supplied, but the vulnerability permits a simple network-based attack that can be executed by sending a crafted packet to the unicast listener. The EPSS score is unavailable, and the flaw has not been listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nevertheless, the potential for service disruption warrants immediate attention.

Generated by OpenCVE AI on October 1, 2026 at 18:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.69 or later where the mod_heartmonitor issue is fixed.
  • If the module is not required, disable or remove mod_heartmonitor from the server configuration.
  • Restrict network access to the unicast listener using firewall rules to limit connections to trusted hosts.

Generated by OpenCVE AI on October 1, 2026 at 18:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache Software Foundation
Apache Software Foundation apache Http Server
Vendors & Products Apache Software Foundation
Apache Software Foundation apache Http Server

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Title Apache HTTP Server: mod_heartmonitor denial of service
Weaknesses CWE-476
References

Subscriptions

Apache Software Foundation Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T16:18:32.908Z

Reserved: 2026-05-17T14:18:39.243Z

Link: CVE-2026-46729

cve-icon Vulnrichment

Updated: 2026-10-01T16:18:28.462Z

cve-icon NVD

Status : Received

Published: 2026-10-01T16:17:44.293

Modified: 2026-10-01T17:17:25.160

Link: CVE-2026-46729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:15:10Z

Weaknesses