{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n us...@httpd.apache.org",
  "subject": "CVE-2026-93546: Apache HTTP Server: mod_dav_fs namespace overflow",
  "message-id": "<2549d1f5-f5d9-2749-a3e1-ba59561e1054@apache.org>",
  "mid": "mjwl5gxgslkfv971r9hl604oqhtv7kfj",
  "permalinks": [
    "mjwl5gxgslkfv971r9hl604oqhtv7kfj",
    "r6825c220cb41d9bf931e6b4c5e76a9f472786141f1b27b80bc096e5e@<announce.apache.org>"
  ],
  "dbid": "2a2fb6829f1fcc65f49a67b3070da967ba51db1c37790ec429a65940cfa08d4b",
  "cc": "us...@httpd.apache.org",
  "epoch": 1790878181,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:09:41",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: moderate \n\nAffected versions:\n\n- Apache HTTP Server through 2.4.68\n\nDescription:\n\nInteger overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.\n\nCredit:\n\nZhen Kong (finder)\nCalif.io in collaboration with Anthropic (finder)\nAISLE in partnership with Red Hat (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-93546\n\nTimeline:\n\n2026-07-28: reported\n2026-10-01: fixed in 2.4.x by r1938682\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: moderate \n\nAffected versions:\n\n- Apache HTTP Server through 2.4.68\n\nDescription:\n\nInteger overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client wit",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3317,
  "id": "mjwl5gxgslkfv971r9hl604oqhtv7kfj"
}