NULL pointer dereference in Apache HTTP Server - CVE-2026-33007
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in mod_authn_socache when handling requests in a caching forward proxy configuration. A remote attacker can send a malicious request to cause a denial of service.
The issue crashes a child process only in a caching forward proxy configuration.