apache http-server CVE-2020-13950 vulnerability in Apache and Other Products
Published on June 10, 2021

mod_proxy_http NULL pointer dereference

product logo product logo product logo product logo product logo
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

Vendor Advisory Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2020-13950

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-13950 are published in these products:

 
 
 
 
 
 
 

Affected Versions

Apache Software Foundation Apache HTTP Server:

Exploit Probability

EPSS
19.46%
Percentile
95.26%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.