Description

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

INFO

Published Date :

2026-05-04T14:48:29.832Z

Last Modified :

2026-05-05T20:23:49.062Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2026-29169 vulnerability.

Vendors Products
Apache
  • Http Server
Apache Software Foundation
  • Apache Http Server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-29169.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact