CVE-2026-42528

Published Oct 1, 2026

Last updated 2 days ago

Overview

Description
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
Source
security@apache.org
NVD status
Undergoing Analysis
Products
http_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-789

Social media

Hype score
Not currently trending

Configurations