CVE-2026-33007Patch(apache / http_server)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache http_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-05); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-04: 1Mentions · 2026-05-05: 2Mentions · 2026-05-11: 2Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-11: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 105-0405-0505-11
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-052
Patch2
2026-05-112
Patch2
Full discourse5 posts
  • Frank@jedisct1
    Patch

    At least 4 vulnerabilities fixed in Apache 2.4.67 were already independently found by Swival https://github.com/Swival/security-audits/tree/main/apache-httpd#apache-httpd-audit-findings (CVE-2026-33857 is #175, CVE-2026-34032 is #176, CVE-2026-28780 is #174, CVE-2026-33007 is #109)

    Post summary

    Four CVEs affecting Apache 2.4.67 were identified in an external audit and the software has been updated to fix them.

    200301.2K
    17.4K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    The post announces a Kusanagi httpd24 module update that patches several CVEs, but provides no further technical or exploit details.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    The post announces a Kusanagi 9 module update, specifically upgrading httpd24 to 2.4.67-1.el9, which patches several CVEs, but offers no further technical or exploit details.

    0101062
    200 followersView on X
  • PHP Sources@phpsources
    Patch

    Apache 2.4.67 corrige des vulnérabilités critiques (CVE-2026-23918, CVE-2026-33007) dans HTTP/2 et mod_proxy_ajp. Mise à jour de sécurité urgente recommandée. Downloader : https://phpsources.net/script/php/apache/60-71_apache,2.4.67 #PHP #CodeGratuit #Developpement #WebDev https://t.co/V32uodzxJf

    Post summary

    Apache 2.4.67 brings critical fixes for CVE‑2026‑23918 and CVE‑2026‑33007 affecting HTTP/2 and mod_proxy_ajp; an urgent security update is recommended.

    0000093
    350 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33007 NULL Pointer Dereference in Apache HTTP Server 2.4.66 mod_authn_socache https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33007

    Post summary

    The text reports a new CVE (CVE-2026-33007) describing a NULL pointer dereference in Apache HTTP Server's mod_authn_socache, with no PoC, exploit, or patch information provided.

    0000054
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more