{"id":"CVE-2026-42528","title":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue","summary":"A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-789"],"vendor":"Apache Software Foundation","product":"Apache HTTP Server","affected":["apache_http_server <= 2.4.68"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:30:25.943","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42528","references":[{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","label":"security@apache.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T16:20:41.491692Z"},"ingestedAt":"2026-10-01T18:55:42.356Z","slug":"CVE-2026-42528","body":"## Overview\n\nA memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}