Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache HTTP Server: integer overflow

High8.8CVE-2026-93546 · Published Oct 1, 2026 · updated Oct 5, 2026

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
<= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1
Apache HTTP Server: out-of-bounds write
High7.5Oct 1