CVE-2026-42528 PUBLISHED

Apache HTTP Server: mod_dav shared lock overflow

Assigner: apache
Reserved: 28.04.2026 Published: 01.10.2026 Updated: 01.10.2026

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.

Users are recommended to upgrade to version 2.4.69, which fixes this issue

Product Status

Vendor Apache Software Foundation
Product Apache HTTP Server
Versions Default: unaffected
  • affected from 0 to 2.4.68 (incl.)

Credits

  • Zhenpeng (Leo) Lin at depthfirst finder

References

Problem Types

  • CWE-789 Memory Allocation with Excessive Size Value CWE