- Description
- A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
- Source
- security@apache.org
- NVD status
- Undergoing Analysis
- Products
- http_server
CVSS 3.1
- Type
- Secondary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- Severity
- MEDIUM
- security@apache.org
- CWE-789
- Hype score
- Not currently trending
🚨 CVE-2026-42528: Apache HTTP Server WebDAV Lock Flaw Crashes Child Processes in 2.4.0-2.4.68 Critical Vulnerability Alert! Apache HTTP Server is affected by CVE-2026-42528. 🔍 Identify Targets via ZoomEye: Search Dork: app="Apache httpd" Exposure: 596.5m instances identi
@zoomeyebot
4 Oct 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache HTTP Serverの脆弱性(Moderate: CVE-2026-42528, CVE-2026-57941, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546, Low: 複数)と2.4.69リリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache https://t.co/4ojFmLmJOj
@omokazuki
1 Oct 2026
100 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6735AACD-F413-409D-A344-874F486E0A7C",
"versionEndExcluding": "2.4.69",
"versionStartIncluding": "2.4.60",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]