CVE-2026-42535
Apache Software Foundation Apache HTTP Server, http server
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
- CVSS
- 9.1
- EPSS
- 0.54% 42.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.09