{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-46729: Apache HTTP Server: mod_heartmonitor denial of service",
  "message-id": "<ad4aa830-88e1-13f0-3542-7ec527e7bd62@apache.org>",
  "mid": "3zpv62pr2fd45dddycb01gt6571qk8p9",
  "permalinks": [
    "3zpv62pr2fd45dddycb01gt6571qk8p9",
    "r97bf2caa5a3ea0f113f93e961d1b9a796c637a6f1af0c2913cb3f59b@<dev.httpd.apache.org>"
  ],
  "dbid": "62bc765395b302377ccf8e1da94833be999ed4ab4d8b6c9852d6bbc37450643f",
  "cc": "",
  "epoch": 1790877794,
  "list": "<dev.httpd.apache.org>",
  "list_raw": "<dev.httpd.apache.org>",
  "date": "2026/10/01 18:03:14",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nNULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.\n\nCredit:\n\nZhang San (finder)\nAnkit Prateek (OffByQuant) (finder)\nZhen Kong (finder)\nSeungHyun Cho of KISA (finder)\n4ra1n, pyn3rd and unam4 (finder)\nRyoma Nishioka (finder)\nKeita Sode (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-46729\n\nTimeline:\n\n2026-05-07: reported\n2026-10-01: fixed in 2.4.x by r1938654\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nNULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener.\n\n\n\nThi",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@httpd.apache.org",
  "size": 3853,
  "id": "3zpv62pr2fd45dddycb01gt6571qk8p9"
}