CVE-2026-29169Disclosure(apache / http_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache http_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 105-0405-0505-12
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-051
General1
2026-05-121
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    General

    Apache httpd CVE-2026-29169 "fixed in 2.4.66" was an error https://www.openwall.com/lists/oss-security/2026/05/05/12 2 more (11 total): CVE-2026-29168: mod_md unrestricted OCSP response https://www.openwall.com/lists/oss-security/2026/05/05/6 CVE-2026-28780: Buffer overflow in mod_proxy_ajp via ajp_msg_check_header() https://www.openwall.com/lists/oss-security/2026/05/05/9

    Post summary

    A concise note lists three Apache httpd CVEs, highlights a patch for one, and flags one as erroneous, with links to discussion threads.

    00030321
    4.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Apache HTTP Server の 5 件の脆弱性が FIX:広大な攻撃範囲を持つ RCE など https://iototsecnews.jp/2026/05/05/critical-apache-http-server-flaw-exposes-millions-of-servers-to-rce-attacks/ 今回の脆弱性の主な原因は、メモリ管理の不備や設定の不備にあります。最も深刻な CVE-2026-23918 は、一度解放されたメモリをプログラムが誤って解放してしまう double-free という現象が HTTP/2 の処理中に発生します。これによりメモリの状態が壊れ、攻撃者に操作される恐れがあります。また CVE-2026-24072 では設定ファイルの評価処理の不備から、本来見えないはずのファイルが読み取られてしまいます。他にも CVE-2026-28780 のような容量制限を超えてデータが書き込まれるバッファ・オーバーフローや、CVE-2026-29168 のリソース割り当て制限の不足、CVE-2026-29169 の NULL ポインタ参照など、プログラムが想定外の挙動をする隙が原因となっています。ご利用のチームは、ご注意ください。 #Apache #CVE202623918 #CVE202624072 #CVE202628780 #CVE202629168 #CVE202629169 #HTTPServer #Vulnerability

    Post summary

    The article reports that five critical Apache HTTP Server vulnerabilities have been fixed, providing detailed technical descriptions of each flaw but not mentioning active exploitation or a PoC.

    01000152
    491 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29169 NULL Pointer Dereference in Apache HTTP Server mod_dav_lock 2.4.66 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29169

    Post summary

    The text announces a NULL Pointer Dereference vulnerability (CVE‑2026‑29169) affecting Apache HTTP Server's mod_dav_lock 2.4.66, with no PoC or exploitation details provided.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more