Integer overflow in Apache HTTP Server - CVE-2026-93546
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service and corrupt a directory's property database.
The vulnerability exists due to an integer overflow in mod_dav_fs when processing PROPPATCH requests declaring many XML namespaces. A remote user can send a crafted PROPPATCH request to cause a denial of service and corrupt a directory's property database.
Write access to WebDAV resources is required.