Apache HTTP Server 2.4.68 及更早版本中的 mod_dav_fs 模块存在整数溢出漏洞。拥有写权限的已认证 WebDAV 客户端可通过发送声明大量 XML 命名空间的 PROPPATCH 请求,导致 worker 进程崩溃,并持久性地损坏目录的属性数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | 0 ~ 2.4.68 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream extern |
| CVE-2026-94250 | 8.2 HIGH | Apache APISIX: Batch response aggregation can exhaust worker memory |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX: unauthenticated impersonation issue in saml-auth |
| CVE-2026-94269 | 6.3 MEDIUM | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX: data-mask may fail to redact request headers in logger output |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-94276 | 5.1 MEDIUM | Apache APISIX: Openid-connect introspection validation issue |
| CVE-2026-94220 | 2.1 LOW | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin |
| CVE-2026-56153 | Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char | |
| CVE-2026-42528 | Apache HTTP Server: mod_dav shared lock overflow | |
| CVE-2026-42356 | Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI direct | |
| CVE-2026-46729 | Apache HTTP Server: mod_heartmonitor denial of service | |
| CVE-2026-47360 | Apache HTTP Server: mod_session: Session cookie not removed during internal redirect | |
| CVE-2026-48005 | Apache HTTP Server: mod_auth_digest reauthentication attack | |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | |
| CVE-2026-56154 | Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} | |
| CVE-2026-56449 | Apache HTTP Server: mod_proxy_html: crash in dump_content | |
| CVE-2026-57941 | Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-ent | |
| CVE-2026-58415 | Apache HTTP Server: mod_dav_fs property database read access | |
| CVE-2026-59685 | Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on C |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet