CVE-2021-26690
mod_session NULL pointer dereference
- Published
- Jun 10, 2021
- Updated
- Aug 3, 2024
- Assigning CNA
- apache
- Evidence observed
- Aug 7, 2026
mod_session NULL pointer dereference
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
CVE-2021-26690 patch diffing - Apache HTTP mod_session NULL pointer dereference
Proof-of-concept exploit for CVE-2021-26690, demonstrating a specific web application vulnerability with exploitation code.
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.