NULL pointer dereference in Apache HTTP Server - CVE-2026-29169
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in mod_dav_lock when handling requests. A remote attacker can send a malicious request to cause a denial of service.
mod_dav_lock is not used internally by mod_dav or mod_dav_fs, and the only known use-case mentioned is mod_dav_svn earlier than version 1.2.0.