A path handling issue in mod_dav_fs in Apache 2.4.67 and...
Critical severity
Unreviewed
Published
Jun 8, 2026
to the GitHub Advisory Database
•
Updated Jun 9, 2026
Description
Published by the National Vulnerability Database
Jun 8, 2026
Published to the GitHub Advisory Database
Jun 8, 2026
Last updated
Jun 9, 2026
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
References