Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache HTTP Server: exposed files

Medium5.3CVE-2026-58415 · Published Oct 1, 2026 · updated Oct 5, 2026

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
>= 2.4.0, <= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: out-of-bounds write
High7.5Oct 1