CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure
A NULL pointer dereference in modxml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.69
Event History
Frequently Asked Questions
Which deployments are exposed to this denial of service?
Apache HTTP Server installations before 2.4.69 are affected when mod_xml2enc processes proxied responses from an untrusted backend server. The issue applies on all platforms.
What must an attacker control to trigger the crash?
The attacker needs an untrusted backend server to return a proxied response with a charset whose conversion partially succeeds and then fails. This condition can cause mod_xml2enc to dereference a NULL pointer and crash.
What is the recommended remediation?
Upgrade Apache HTTP Server to version 2.4.69, which fixes the issue.