CVE-2026-42535
published 2026-06-08CVE-2026-42535: A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
0.54%
41.8th percentile
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.68 | 2.4.68 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | <= 2.4.67 | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
vendor_ubuntu9.8CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-20·CVSS 5.3
CVE-2026-34032 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this i
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-07-08·CVSS 9.8
CVE-2026-44119 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. An attacker
could use this issue to cause the server to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this
Red Hat
httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
vendor_redhat·2026-06-08·CVSS 9.1
CVE-2026-42535 [CRITICAL] CWE-22 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A flaw was found in the `mod_dav_fs` module of Apache HTTP Server. A WebDAV (Web Distributed Authoring and Versioning) content author could exploit a path handling issue to directly manipulate trusted DAV property databases. This manipulation could potentially lead to child process crashes, resulting in a Denial of Service (DoS).
Package: httpd (Red Hat Enterprise Linux 10) - Fix deferred
Package: httpd (Red Hat Enterprise Linux 6) - Fix deferre
VulDB
Apache HTTP Server up to 2.4.67 mod_dav_fs denial of service (EUVD-2026-35090)
vuldb·2026-06-09
CVE-2026-42535 [LOW] Apache HTTP Server up to 2.4.67 mod_dav_fs denial of service (EUVD-2026-35090)
A vulnerability was found in Apache HTTP Server up to 2.4.67. It has been rated as problematic. This affects an unknown function of the component mod_dav_fs. Performing a manipulation results in denial of service.
This vulnerability is identified as CVE-2026-42535. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
ghsa_unreviewed·2026-06-08
CVE-2026-42535 [CRITICAL] CWE-668 A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue [fedora-all]
bugzilla·2026-06-12·CVSS 9.1
CVE-2026-42535 [CRITICAL] CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue [fedora-all]
CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
bugzilla·2026-06-08·CVSS 9.1
CVE-2026-42535 [CRITICAL] CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
2026-06-08
Published