The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.
Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4571-1 | [ERRATUM] [DLA 4571-1] apache2 security update |
Debian DSA |
DSA-6248-1 | apache2 security update |
Ubuntu USN |
USN-8239-1 | Apache HTTP Server vulnerabilities |
Wed, 13 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 05 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 05 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache http Server |
|
| CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache http Server |
Mon, 04 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 04 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache Software Foundation
Apache Software Foundation apache Http Server |
|
| Vendors & Products |
Apache Software Foundation
Apache Software Foundation apache Http Server |
Mon, 04 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock. | |
| Title | Apache HTTP Server: mod_dav_lock indirect lock crash | |
| Weaknesses | CWE-476 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-05T20:23:49.062Z
Reserved: 2026-03-04T11:50:32.014Z
Link: CVE-2026-29169
Updated: 2026-05-05T20:23:49.062Z
Status : Modified
Published: 2026-05-04T15:16:03.720
Modified: 2026-05-05T21:16:21.930
Link: CVE-2026-29169
OpenCVE Enrichment
Updated: 2026-05-04T17:30:04Z
Debian DLA
Debian DSA
Ubuntu USN