High severity7.5NVD Advisory· Published May 4, 2026· Updated May 5, 2026
CVE-2026-29169
CVE-2026-29169
Description
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.
The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.
Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: <2.4.67
- (no CPE)range: <=2.4.66
- Range: <1.2.0
- osv-coords16 versionspkg:bitnami/apachepkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.4.67+ 15 more
- (no CPE)range: < 2.4.67
- (no CPE)range: < 2.4.67-1.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
- (no CPE)range: < 2.4.66-160000.2.1
Patches
Vulnerability mechanics
References
3- www.openwall.com/lists/oss-security/2026/05/04/20nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- www.openwall.com/lists/oss-security/2026/05/05/12nvd
News mentions
2- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026
- Critical, High-Severity Vulnerabilities Patched in Apache MINA, HTTP ServerSecurityWeek · May 5, 2026