PT-2026-37663 · Bitnami · Apache

Published

2026-05-06

·

Updated

2026-05-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A NULL pointer dereference in mod dav lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod dav lock is not used internally by mod dav or mod dav fs.
The only known use-case for mod dav lock was mod dav svn from Apache Subversion earlier than version 1.2.0.
Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod dav lock.

Related Identifiers

BIT-APACHE-2026-29169

Affected Products

Apache