CVE-2026-46729·Apache vulnerability
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.60
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to resolve a null pointer dereference flaw in the mod_heartmonitor module that can cause denial of service. Organizations running versions 2.4.60 through 2.4.68 should prioritize this update, especially if heartbeat monitoring over unicast listeners is enabled in their configuration. After patching, restart the Apache service and verify the new version is running.
sudo dnf update httpd && sudo systemctl restart httpdDefensia detects this vulnerability
How to check if you are affected
- Check the current Apache version: apache2ctl -v (Ubuntu/Debian) or httpd -v (RHEL/CentOS)
- Verify if mod_heartmonitor is loaded: grep -i heartmonitor /etc/apache2/mods-enabled/* or grep -i heartmonitor /etc/httpd/conf.modules.d/*
- Search Apache error logs for segmentation faults or null pointer errors: grep -i 'segmentation\|null pointer\|heartmonitor' /var/log/apache2/error.log or /var/log/httpd/error_log
- Confirm the patch by re-running apache2ctl -v or httpd -v and verifying the version is 2.4.69 or later
FAQ
What is CVE-2026-46729?
CVE-2026-46729 is a null pointer dereference vulnerability in Apache's mod_heartmonitor module that occurs when processing unicast listener traffic, allowing remote attackers to crash the web server and cause a denial of service condition.
Is CVE-2026-46729 being actively exploited?
No, this vulnerability is not currently listed as actively exploited in the CISA Known Exploited Vulnerabilities catalog, and no public proof-of-concept exploits are available.
What versions of Apache are affected by CVE-2026-46729?
Apache HTTP Server versions 2.4.60 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-46729?
Run 'apache2ctl -v' or 'httpd -v' and check if the version is between 2.4.60 and 2.4.68. If mod_heartmonitor is enabled (check with 'grep heartmonitor /etc/apache2/mods-enabled/*'), your server is at risk.
Does Defensia detect CVE-2026-46729?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-46729 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-46729. Free for 1 server.
Get started free