CVE-2020-13950: mod_proxy_http NULL pointer dereference
A flaw was found In Apache httpd. The modproxy has a NULL pointer dereference. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Apache HTTP Server versions 2.4.41 to 2.4.46 modproxyhttp can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in Apache httpd?
The vulnerability ID is CVE-2020-13950.
What is the severity of CVE-2020-13950?
The severity of CVE-2020-13950 is high, with a severity value of 7.5.
Which version of Apache httpd is affected by CVE-2020-13950?
Apache httpd versions 2.4.41 to 2.4.46 are affected by CVE-2020-13950.
How can CVE-2020-13950 be exploited?
CVE-2020-13950 can be exploited by sending specially crafted requests using both Content-Length and Transfer-Encoding headers.
How can I fix the CVE-2020-13950 vulnerability?
To fix the CVE-2020-13950 vulnerability, update your Apache httpd version to 2.4.47 or later.