CVE-2019-12412: Apache LIBAPREQ2

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

Affected products

  • Apache LIBAPREQ2: from 2.07, up to and including 2.13

Published 2020-11-19. Last modified 2026-06-17.