CVE-2026-42528·Apache vulnerability
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
- Severity
- medium
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.60
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Organizations running Apache httpd versions 2.4.60 through 2.4.68 should immediately upgrade to version 2.4.69 or later to patch a memory calculation flaw in the mod_dav module. This vulnerability can be exploited by authenticated users with WebDAV lock creation privileges to trigger denial-of-service conditions through child process crashes. Prioritize this update for production web servers that expose WebDAV functionality.
sudo dnf update httpdDefensia detects this vulnerability
How to check if you are affected
- Run 'apache2ctl -v' or 'httpd -v' to display the currently installed Apache version and confirm if it falls within the 2.4.60-2.4.68 range
- Execute 'apache2ctl -M | grep dav' (or 'httpd -M | grep dav') to verify whether mod_dav is loaded and active on the server
- Search Apache access and error logs for WebDAV LOCK request patterns: grep -i 'LOCK' /var/log/apache2/access.log or equivalent error log path
- After patching, re-run 'apache2ctl -v' to confirm the version is 2.4.69 or higher, and restart Apache with 'sudo systemctl restart apache2' to apply changes
FAQ
What is CVE-2026-42528?
CVE-2026-42528 is a memory calculation vulnerability in Apache httpd's mod_dav module that allows authenticated users with WebDAV lock creation permissions to crash server worker processes, resulting in denial of service. The flaw stems from incorrect memory size computations when processing lock-related operations.
Is CVE-2026-42528 being actively exploited?
No, this vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available. However, the attack requires only authenticated access to WebDAV, making it a practical threat in environments where untrusted users have such permissions.
What versions of Apache are affected by CVE-2026-42528?
Apache httpd versions 2.4.60 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix. Earlier versions (2.4.59 and below) are not affected.
How do I check if my server is vulnerable to CVE-2026-42528?
Run 'httpd -v' or 'apache2ctl -v' and check if the version output is between 2.4.60 and 2.4.68. If mod_dav is loaded (verify with 'httpd -M | grep dav'), and the version is in the vulnerable range, your server is at risk.
Does Defensia detect CVE-2026-42528?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-42528 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42528. Free for 1 server.
Get started free