Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86019.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-86019
Upstream
Published
2026-05-04T15:16:03Z
Modified
2026-08-28T17:47:37Z
Summary
CVE-2026-29169 affecting package httpd for versions less than 2.4.67-1
Details

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.

The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.

Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

References

Affected packages

Azure Linux:3 / httpd

Package

Name
httpd
Purl
pkg:rpm/azure-linux/httpd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.67-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86019.json"