{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-63686: Apache HTTP Server: mod_xml2enc crash on charset conversion failure",
  "message-id": "<b231073a-ca53-3bd2-ecd9-b07f8eaf03e6@apache.org>",
  "mid": "tf9vz8r789bdblk543h2qdwsq5l92sbm",
  "permalinks": [
    "tf9vz8r789bdblk543h2qdwsq5l92sbm",
    "r100a311797edf7eb0e3e5708d8a4400ff00f79af4ad1b82b54bcf0f9@<announce.apache.org>"
  ],
  "dbid": "8ce9247c181690cab2bd9c1cf0cc302862b7eba11da1d63e142944b3aeb8f1eb",
  "cc": "de...@httpd.apache.org",
  "epoch": 1790878189,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:09:49",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nA NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.\n\nCredit:\n\nLucian Nitescu (finder)\nZhen Kong (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-63686\n\nTimeline:\n\n2026-06-14: Report received\n2026-10-01: fixed in 2.4.x by r1938678\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nA NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3368,
  "id": "tf9vz8r789bdblk543h2qdwsq5l92sbm"
}