CVE-2026-42528 is a vulnerability in Apache HTTP Server
Published on October 1, 2026
Apache HTTP Server: mod_dav shared lock overflow
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.
Users are recommended to upgrade to version 2.4.69, which fixes this issue
Vulnerability Analysis
CVE-2026-42528 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Timeline
Report received
fixed in 2.4.x by r1938652 157 days later.
2.4.69 released
Weakness Type
What is a Stack Exhaustion Vulnerability?
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
CVE-2026-42528 has been classified to as a Stack Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-42528
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Before and including 2.4.68 is affected.