Description
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Denial of Service and data integrity compromise
Action: Apply patch
AI Analysis

Impact

Integer overflow in mod_dav_fs allows an authenticated WebDAV client with write access to issue PROPPATCH requests containing many XML namespaces, which triggers a crash in worker processes and permanently corrupts a directory’s property database.

Affected Systems

The vulnerability affects Apache HTTP Server versions up to and including 2.4.68. Only installations that have enabled the mod_dav_fs module and allow WebDAV write access are impacted.

Risk and Exploitability

Although the CVSS score is not provided, the flaw requires authentication and write permission, which limits the attack surface. The attack vector is likely an authenticated WebDAV client that can manipulate namespace declarations. Because it is not listed in CISA’s KEV catalog and no EPSS score is available, the likelihood of exploitation appears moderate, but the potential impact of a denial of service or data corruption can be severe for web applications relying on WebDAV functionality.

Generated by OpenCVE AI on October 1, 2026 at 18:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.69 or later, where the integer overflow in mod_dav_fs has been resolved.
  • If an upgrade is not immediately possible, restrict or disable WebDAV write access for users that do not require it, thereby reducing the attack surface.
  • Monitor server logs for abnormal PROPPATCH activity and apply additional logging or rate limiting to detect and mitigate potential abuse.

Generated by OpenCVE AI on October 1, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Http Server
Vendors & Products Apache
Apache apache Http Server

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Title Apache HTTP Server: mod_dav_fs namespace overflow
Weaknesses CWE-190
References

Subscriptions

Apache Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:35.921Z

Reserved: 2026-09-18T09:17:50.552Z

Link: CVE-2026-93546

cve-icon Vulnrichment

Updated: 2026-10-01T19:38:21.692Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:33.313

Modified: 2026-10-01T20:30:25.943

Link: CVE-2026-93546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:30:11Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound