CVE-2021-26690

Updated: 2025-08-20 00:36:46.495219

Description:

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 7 ELS httpd 2.4.6 7.5 HIGH Released CLSA-2023:1696536930 2023-10-05 17:08:38
CentOS 8.4 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2022:1643747448 2022-02-01 23:30:35
CentOS 8.5 ELS httpd 2.4.37 7.5 HIGH Not Vulnerable 2022-02-02 08:34:37
CloudLinux 7 ELS httpd 2.4.6 7.5 HIGH Released CLSA-2024:1726078096 2024-09-18 12:25:30
Oracle Linux 7 ELS httpd 2.4.6 7.5 HIGH Released CLSA-2026:1767949942 2026-01-14 16:30:46
Ubuntu 16.04 ELS apache2 2.4.18 7.5 HIGH Released CLSA-2021:1635459129 2021-12-09 07:57:03
Ubuntu 18.04 ELS apache2 2.4.29 7.5 HIGH Already Fixed 2023-06-02 09:11:09