Vulnerability record · CVE-2018-8011 · published 18 July 2018
CVE-2018-8011: Apache HTTP Server mod_md NULL pointer dereference DoS
Apache · Http Server
Apache HTTP Server 2.4.33 contains a NULL pointer dereference in the mod_md challenge handler. A specially crafted HTTP request causes the child process to segfault, allowing remote denial of service. The flaw is fixed in 2.4.34.
Description
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability, no authentication, and high EPSS percentile make this a serious availability risk despite no KEV listing.
What it is
Apache HTTP Server 2.4.33 contains a NULL pointer dereference in the mod_md challenge handler. A specially crafted HTTP request causes the child process to segfault, allowing remote denial of service. The flaw is fixed in 2.4.34.
Impact
An unauthenticated remote attacker can crash Apache child processes, disrupting or denying service to legitimate users. No data confidentiality or integrity impact is described.
Attack surface
Reachable over the network via HTTP requests to a server running the affected mod_md challenge handler. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high (0.56037, 98.999th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Apache HTTP Server to 2.4.34 or later, which fixes the mod_md NULL pointer dereference.
- If immediate upgrade is not possible, disable or remove the mod_md module until patched.
- Apply vendor advisories for NetApp products that bundle the affected Apache HTTP Server.
- Monitor Apache error logs for child process segfaults and restart storms as a compensating control.
Detection
- Alert on Apache child process segfault or crash events correlated with inbound HTTP requests.
- Monitor for repeated worker process restarts or abrupt connection resets on mod_md-enabled hosts.
- Review HTTP request logs for anomalous or malformed requests targeting ACME challenge paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-8011 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-8011), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.