CVE-2018-8011 is a denial-of-service vulnerability affecting Apache HTTP Server versions 2.4.33, specifically within the mod_md challenge handler. Specially crafted HTTP requests can trigger a NULL pointer dereference, causing the child process to crash and effectively denying service to legitimate users. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While no public exploit code or active exploitation has been observed, its high EPSS and FAUCET Risk Score indicate a significant potential impact, and it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.33CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.4.33:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_md: NULL pointer dereference causing httpd child process crash
Jul 18, 2018Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project