From: Eric Covener <[email protected]>
Reply-To: <[email protected]>

Severity: moderate 

Affected versions:

- Apache HTTP Server through 2.4.68

Description:

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an 
authenticated WebDAV client with write access to crash worker processes and 
persistently corrupt a directory's property database via PROPPATCH requests 
declaring many XML namespaces.

Credit:

Zhen Kong (finder)
Calif.io in collaboration with Anthropic (finder)
AISLE in partnership with Red Hat (finder)

References:

https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-93546

Timeline:

2026-07-28: reported
2026-10-01: fixed in 2.4.x by r1938682
2026-10-01: 2.4.69 released


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to