Sceawere
Vulnerability Detail
CVE-2026-93546UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache mod_dav_fs Integer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-190 Integer overflow or wraparound
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-01T17:17:33.313Z",
"pubdate": "2026-10-01T17:17:33.313Z",
"executiveSummary": "An integer overflow vulnerability exists in the mod_dav_fs module of the Apache HTTP Server, affecting versions up to and including 2.4.68.\nThe vulnerability allows an authenticated remote attacker with WebDAV write access to trigger a crash in worker processes and achieve persistent corruption of the directory's property database.\nThe root cause resides in improper handling of XML namespace declarations within PROPPATCH requests, leading to integer overflow conditions during processing.\nSuccessful exploitation requires the attacker to possess authenticated access to the WebDAV service. The risk is significant as it facilitates both denial-of-service (DoS) against the Apache worker processes and the integrity compromise of the underlying property database storage.\nThis vulnerability highlights a flaw in input validation mechanisms during the parsing of complex WebDAV requests, specifically when dealing with multiple XML namespaces.",
"technicalDetails": "The vulnerability is situated within the mod_dav_fs component of the Apache HTTP Server, which handles filesystem-backed WebDAV requests. Specifically, the defect is triggered during the processing of PROPPATCH requests, which are used to update properties on a resource.\nThe root cause is an integer overflow occurring when the module parses an excessive number of XML namespace declarations provided in a PROPPATCH request. When these declarations are processed, the internal logic fails to safely validate or bounds-check the resulting integer values used for memory allocation or indexing, causing an overflow condition.\nThe exploitation flow begins with an authenticated attacker submitting a malformed PROPPATCH request containing an unusually high volume of XML namespace definitions. As the server processes this input, the overflow occurs within the logic responsible for managing namespace metadata associated with the WebDAV properties.\nOnce the overflow is triggered, it leads to memory corruption within the context of the Apache worker process. This corruption manifests in two primary ways: first, the destabilization of the worker process typically results in an immediate crash, leading to a denial-of-service condition for that specific process. Second, the incorrect memory handling leads to the improper serialization or writing of property database entries to the disk.\nBecause mod_dav_fs maintains its property database in a persistent format, the corrupted data is written to the server's backend storage. This leads to persistent data corruption where the property database becomes inconsistent or unusable, even after the server process is restarted. Subsequent requests relying on these corrupted entries may encounter further errors or unexpected behavior.\nThe vulnerability affects Apache HTTP Server versions through 2.4.68. It requires the attacker to have already established an authenticated session with sufficient write permissions for the target WebDAV collection. The network exposure is limited to systems where WebDAV is enabled via mod_dav and mod_dav_fs."
}