Posted by Eric Covener on Oct 01 Severity: moderate Affected versions: - Apache HTTP Server through 2.4.68 Description: Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces. Credit: Zhen Kong (finder) Calif.io in collaboration with Anthropic (finder) AISLE in...
CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q4/29
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.






