Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63686

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 23.7%
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved