CVE-2026-93546

Discovered by AISLEPUBLISHEDCWE-190

Description

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

CVSS Base Scores

CVSS v3.1(Primary)
8.8

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionStatus
Apache HTTP Server——

References