Path traversal in Apache HTTP Server - CVE-2026-42535
Published: June 8, 2026
Apache HTTP Server
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper path handling in mod_dav_fs when a WebDAV content author directly manipulates trusted DAV property databases. A remote user can manipulate trusted DAV property databases to cause a denial of service.
The issue may cause child process crashes.