CVE-2026-46729: Apache HTTP Server: mod_heartmonitor denial of service
Published Oct 1, 2026
·Updated
NULL Pointer Dereference vulnerability in Apache HTTP Servers modheartmonitor over unicast listener.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Apache HTTP Server deployments are affected?
Apache HTTP Server versions 2.4.0 through 2.4.68 are affected when mod_heartmonitor is used with a unicast listener.
2
What condition is required to exploit this issue?
The vulnerability is in mod_heartmonitor's handling of a unicast listener. The provided information does not identify any further attacker prerequisites or required request characteristics.
3
What is the impact of successful exploitation?
Successful exploitation can trigger a NULL pointer dereference, resulting in denial of service.