CVE-2026-29169 Details
Description
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
A NULL pointer dereference vulnerability has been identified in the mod_dav_lock module of Apache HTTP Server. This issue affects versions through 2.4.66. The vulnerability may allow an attacker to crash the server by sending a malicious request. The mod_dav_lock module is not used by default in mod_dav or mod_dav_fs, and its only known application is with mod_dav_svn in Apache Subversion versions prior to 1.2.0.
Users are advised to upgrade to Apache HTTP Server version 2.4.67, which addresses this vulnerability. Alternatively, mod_dav_lock can be removed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/04/20 | CVE | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/05/12 | CVE | |
| https://httpd.apache.org/security/vulnerabilities_24.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache http server | < 2.4.67 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | CVE |
| May 5, 2026 | Initial Analysis | [email protected] |
| May 4, 2026 | CVE Modified | CVE |
| May 4, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | New CVE Received | [email protected] |