CVE-2026-29169: Apache HTTP Server: mod_dav_lock indirect lock crash
A NULL pointer dereference in moddavlock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.moddavlock is not used internally by moddav or moddavfs.
The only known use-case for moddavlock was moddavsvn from Apache Subversion earlier than version 1.2.0.
Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove moddavlock.
Other sources
Apache HTTP Server: moddavlock indirect lock crash
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.4.67-1 - Upgrade
Upgrade
Apache HTTP Server (mod_dav_lock)to a version that resolves this vulnerability.Fixed in 2.4.66 - Remove
Remove
Apache HTTP Server module mod_dav_lockfrom your environment.If mod_dav_lock is not needed, remove/uninstall it, as recommended (the only known use-case was mod_dav_svn from Apache Subversion earlier than 1.2.0).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29169?
CVE-2026-29169 has been classified as a moderate severity vulnerability due to its potential to crash the Apache HTTP Server.
How do I fix CVE-2026-29169?
To fix CVE-2026-29169, upgrade to Apache HTTP Server version 2.4.67 or later.
Which versions of Apache HTTP Server are affected by CVE-2026-29169?
CVE-2026-29169 affects Apache HTTP Server versions 2.4.66 and earlier.
Can CVE-2026-29169 be exploited remotely?
Yes, CVE-2026-29169 can be exploited remotely through a crafted malicious request.
Does CVE-2026-29169 impact Apache Subversion?
Yes, CVE-2026-29169 also affects Apache Subversion versions 1.2.0 and earlier.