CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-08 16:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-42535

Mitre link : CVE-2026-42535

CVE.ORG link : CVE-2026-42535


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-668

Exposure of Resource to Wrong Sphere