MEDIUM 5.3 NVD
CVE-2026-58415
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remot
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://www.openwall.com/lists/oss-security/2026/10/01/20
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.