CVE-2026-93546

Summary

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache HTTP Server0 <= 2.4.68affected

Weaknesses

  • CWE-190: CWE-190 Integer overflow or wraparound

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

CVE Program Container

Additional References

References