apache http-server CVE-2026-58415 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_dav_fs property database read access
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Vendor Advisory NVD

Timeline

reported

fixed in 2.4.x by r1938668 99 days later.

2.4.69 released

Weakness Type

Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be. Web servers, FTP servers, and similar servers may store a set of files underneath a "root" directory that is accessible to the server's users. Applications may store sensitive files underneath this root without also using access control to limit which users may request those files, if any. Alternately, an application might package multiple files or directories into an archive file (e.g., ZIP or tar), but the application might not exclude sensitive files that are underneath those directories.


Products Associated with CVE-2026-58415

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: