Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42535

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 6.5

Описание

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A flaw was found in the mod_dav_fs module of Apache HTTP Server. A WebDAV (Web Distributed Authoring and Versioning) content author could exploit a path handling issue to directly manipulate trusted DAV property databases. This manipulation could potentially lead to child process crashes, resulting in a Denial of Service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 8httpdFix deferred
Red Hat Enterprise Linux 9httpdFix deferred
Red Hat Hardened ImageshttpdAffected
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2486406httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 9.1
nvd
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
около 2 месяцев назад

Apache HTTP Server: mod_dav_fs protected directory access

CVSS3: 9.1
debian
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlierallows ...

CVSS3: 9.1
github
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

6.5 Medium

CVSS3