Critical severity9.1NVD Advisory· Published Jun 8, 2026· Updated Jun 9, 2026
CVE-2026-42535
CVE-2026-42535
Description
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
22- Range: <=2.4.67
- osv-coords19 versionspkg:rpm/opensuse/apache2-utils&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-worker&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/apache2-prefork&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/almalinux/mod_sessionpkg:rpm/opensuse/apache2-manual&distro=openSUSE%20Leap%2016.0pkg:bitnami/apachepkg:rpm/opensuse/apache2-event&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/mod_luapkg:rpm/opensuse/apache2-devel&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/mod_sslpkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/httpd-corepkg:rpm/almalinux/httpd-develpkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/httpdpkg:rpm/almalinux/httpd-filesystem
< 2.4.66-160000.3.1+ 18 more
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 1:2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.68
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 1:2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.66-160000.3.1
- (no CPE)range: < 2.4.62-13.el9_8.5
- (no CPE)range: < 2.4.62-13.el9_8.5
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/08/8nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
News mentions
2- Apache HTTP Server and Answer: 22 Vulnerabilities Disclosed, Including Critical FlawsVypr Intelligence · Jun 10, 2026
- Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow FlawsCyber Security News · Jun 9, 2026