CVE-2026-42535: Apache HTTP Server: mod_dav_fs protected directory access
A path handling issue in moddavfs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.68-1~deb13u1Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server (mod_dav_fs)to a version that resolves this vulnerability.Fixed in 2.4.68Patch CVE-2026-42535
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42535?
CVE-2026-42535 has a risk rating of 23.
How do I fix CVE-2026-42535?
To fix CVE-2026-42535, upgrade your Apache HTTP Server to version 2.4.68 or later.
What versions of Apache are affected by CVE-2026-42535?
CVE-2026-42535 affects Apache HTTP Server version 2.4.67 and earlier.
What are the potential consequences of CVE-2026-42535?
The potential consequences of CVE-2026-42535 include the possibility of child process crashes due to manipulated trusted DAV property databases.
Who should be concerned about CVE-2026-42535?
WebDAV content authors and administrators using affected versions of Apache HTTP Server should be concerned about CVE-2026-42535.