Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42535

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 6.5

Описание

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

A flaw was found in the mod_dav_fs module of Apache HTTP Server. A WebDAV (Web Distributed Authoring and Versioning) content author could exploit a path handling issue to directly manipulate trusted DAV property databases. This manipulation could potentially lead to child process crashes, resulting in a Denial of Service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 8httpd:2.4/httpdFix deferred
Red Hat JBoss Core Servicesmod_dav_fs.soAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_proxy_clusterFixedRHSA-2026:5686819.08.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2026:5686819.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2486406httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 9.1
nvd
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
3 месяца назад

Apache HTTP Server: mod_dav_fs protected directory access

CVSS3: 9.1
debian
3 месяца назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlierallows ...

CVSS3: 9.1
redos
около 2 месяцев назад

Уязвимость httpd

6.5 Medium

CVSS3