CVE-2026-46729 PUBLISHED

Apache HTTP Server: mod_heartmonitor denial of service

Assigner: apache
Reserved: 17.05.2026 Published: 01.10.2026 Updated: 01.10.2026

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Product Status

Vendor Apache Software Foundation
Product Apache HTTP Server
Versions Default: unaffected
  • affected from 2.4.0 to 2.4.68 (incl.)

Credits

  • Zhang San finder
  • Ankit Prateek (OffByQuant) finder
  • Zhen Kong finder
  • SeungHyun Cho of KISA finder
  • 4ra1n, pyn3rd and unam4 finder
  • Ryoma Nishioka finder
  • Keita Sode finder

References

Problem Types

  • CWE-476 NULL Pointer Dereference CWE