NULL pointer dereference in Apache HTTP Server - CVE-2026-63686
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in mod_xml2enc when processing a proxied response with a charset conversion that partially succeeds and then fails. A remote attacker can provide a specially crafted proxied response to cause a denial of service.