A security notice published on October 1, 2026 rates an Apache HTTP Server flaw as low severity. Remote clients may read certain WebDAV properties through the .DAV state directory.
A security notice published on October 1, 2026 describes CVE-2026-58415 in Apache HTTP Server's mod_dav_fs. The stated severity is low, and the issue affects versions 2.4.0 through 2.4.68 on all platforms.
According to the notice, a remote client can send a GET request to the .DAV state directory and read “dead” WebDAV properties of resources it cannot modify. The report attributes the exposure to internal state files accessible to third parties. The indicated fix is version 2.4.69.
To assess exposure, identify the server version and confirm whether mod_dav_fs is in use. Compare your installation with the original oss-sec notice and the project's official documentation; the feed's translated summary may not include every detail.
If your installation is in the affected range, follow official upgrade guidance and test the change in your environment. Avoid exposing the .DAV directory and check state-file permissions. The notice does not say that every installation is exploitable or that the flaw allows modification of these resources.