CVE-2026-42535

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Scoring

Severity
CRITICAL
CVSS base score
9.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS probability
0.54%
CWE
CWE-668
Published
2026-06-08
Last modified
2026-06-09

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs