ZeroHour

CVE-2026-42535

CVSS 3.1
9.1 critical
EPSS
<1%p44
Published
()
Modified
Description

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Vendors
apache
Products
http server
Weakness
CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.