{"api_version":"1","generated_at":"2026-10-01T21:51:01+00:00","cve":"CVE-2026-42528","urls":{"html":"https://cve.report/CVE-2026-42528","api":"https://cve.report/api/cve/CVE-2026-42528.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-42528","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528"},"summary":{"title":"Apache HTTP Server: mod_dav shared lock overflow","description":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue","state":"PUBLISHED","assigner":"apache","published_at":"2026-10-01 16:17:43","updated_at":"2026-10-01 21:17:20"},"problem_types":["CWE-789","CWE-789 CWE-789 Memory Allocation with Excessive Size Value"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/12","name":"http://www.openwall.com/lists/oss-security/2026/10/01/12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","name":"https://httpd.apache.org/security/vulnerabilities_24.html","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-42528","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache HTTP Server","version":"affected 2.4.68 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-04-27T17:33:00.000Z","lang":"en","value":"Report received"},{"source":"CNA","time":"2026-10-01T12:00:00.000Z","lang":"en","value":"fixed in 2.4.x by r1938652"},{"source":"CNA","time":"2026-10-01T12:00:00.000Z","lang":"eng","value":"2.4.69 released"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Zhenpeng (Leo) Lin at depthfirst","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-42528","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-01T16:20:41.491692Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T16:20:44.093Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-10-01T20:09:18.998Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/12"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache HTTP Server","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.4.68","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Zhenpeng (Leo) Lin at depthfirst"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.<br><br>Users are recommended to upgrade to version 2.4.69, which fixes this issue<br>"}],"value":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue"}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-789","description":"CWE-789 Memory Allocation with Excessive Size Value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T15:52:51.682Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://httpd.apache.org/security/vulnerabilities_24.html"}],"source":{"discovery":"EXTERNAL"},"timeline":[{"lang":"en","time":"2026-04-27T17:33:00.000Z","value":"Report received"},{"lang":"en","time":"2026-10-01T12:00:00.000Z","value":"fixed in 2.4.x by r1938652"},{"lang":"eng","time":"2026-10-01T12:00:00.000Z","value":"2.4.69 released"}],"title":"Apache HTTP Server: mod_dav shared lock overflow","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-42528","datePublished":"2026-10-01T15:52:51.682Z","dateReserved":"2026-04-28T14:47:08.369Z","dateUpdated":"2026-10-01T20:09:18.998Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 16:17:43","lastModifiedDate":"2026-10-01 21:17:20","problem_types":["CWE-789","CWE-789 CWE-789 Memory Allocation with Excessive Size Value"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T16:20:41.491692Z","id":"CVE-2026-42528","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"42528","Ordinal":"1","Title":"Apache HTTP Server: mod_dav shared lock overflow","CVE":"CVE-2026-42528","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"42528","Ordinal":"1","NoteData":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue","Type":"Description","Title":"Apache HTTP Server: mod_dav shared lock overflow"}]}}}