CVE-2020-13950

mod_proxy_http NULL pointer dereference

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service


We have discovered 222,803 live websites that are affected by CVE-2020-13950.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains222,803 live websites (7.06% of Apache install base)
Vulnerable Versions
  • from 2.4.41 through 2.4.41
  • from 2.4.43 through 2.4.43
  • from 2.4.46 through 2.4.46
Vulnerable Versions Count3 versions ( 2.04% of all versions)



Details

  • Published - Jun 10, 2021
  • Updated - Aug 4, 2024

Credits

  • Reported by Marc Stern (<marc.stern approach.be>)

CVE-2020-13950 usage by Country

United States95,164 websites



Germany22,674 websites
Poland14,352 websites
France11,764 websites
Italy6,377 websites
Singapore6,289 websites
Russia5,309 websites
GB4,568 websites
Netherlands4,398 websites
Argentina3,735 websites

CVE-2020-13950 usage by TLD

.com84,351 websites
.pl13,453 websites
.de12,533 websites
.org12,449 websites
.net8,940 websites
.it6,461 websites
.ru4,576 websites
.nl4,033 websites
.ca3,967 websites
.co.uk3,730 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-13950

Top websites that are affected by CVE-2020-13950. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*********.net GB*,***
****.*************.org GB*,***
******.com GB*,***
******.*****.com United States*,***
*************.com France*,***
*******.*******.pl Poland*,***
**********.*************.at Austria*,***
*********.net GB*,***
***.de United States*,***
*******.org Germany*,***
See full domain list

FAQ

A total of 222,803 websites have been identified as vulnerable to CVE-2020-13950, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2020-13950 vulnerability.
Apache versions before, and including, 2.4.46 are vulnerable to CVE-2020-13950.

References