How many worker processes can a single WebDAV lock loop take down
How many worker processes can a single WebDAV lock loop take down Overview CVE-2026-42528 is a denial-of-service defect in Apache HTTP Server that a user with WebDAV lock rights can trigger. The question tha
How many worker processes can a single WebDAV lock loop take down
Overview
CVE-2026-42528 is a denial-of-service defect in Apache HTTP Server that a user with
WebDAV lock rights can trigger. The question that matters for capacity planning is not
whether one request crashes one process. It is how cheaply an attacker can repeat that
request once the fix is still missing.
Apache HTTP Server 2.4.69, published on 1 October 2026, fixes this issue along with
nineteen other flaws. The advisory reports no exploitation in the wild and no public
proof-of-concept.
Mechanism and exploitation conditions
WebDAV uses locks so that two editors do not clobber the same resource. A client sends
LOCK, edits, then sends UNLOCK. mod_dav maintains the lock table behind those calls.
CVE-2026-42528 breaks the handling of a lock request badly enough that the child process
crashing is the outcome instead of an HTTP error. The conditions are configuration
dependent: mod_dav must be loaded, and the caller must hold lock rights. Where WebDAV is
published without authentication, any client meets the second condition.
Impact on the worker pool
Apache httpd answers requests with a pool of child processes or threads and a configured
concurrency limit. When a request kills the worker that serves it, the parent starts a
replacement. Under an idle site, that cycle is invisible.
Under load, the cycle competes with real traffic. Each malformed lock request costs a
worker start, and a small number of clients can sustain that cost indefinitely. Operators
usually notice it as a CPU graph that climbs without matching request volume, followed by
timeouts and connection refusals.
The outcome is availability loss, not data loss or code execution.
Affected products and scope
The advisory applies the 2.4.0 to 2.4.68 range to this class of defect. A host outside
that range, or a host that never loads mod_dav, is not exposed through this path.
Exposure context
A ZoomEye search for app="Apache httpd" returns 596,483,702 assets. This measures the
installed base of servers that advertise the product. It says nothing about which of them
enable WebDAV or accept unauthenticated lock requests.
Remediation and mitigations
Install Apache HTTP Server 2.4.69. Where that is not yet possible, remove mod_dav from
hosts that do not need it, require authentication on WebDAV paths, and cap request rates
per client so a single source cannot sustain the crash loop.
References
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.