CVE-2013-6438 describes a denial-of-service vulnerability in the mod_dav module of the Apache HTTP Server, affecting versions prior to 2.4.8, as well as various distributions including Ubuntu and Oracle. The flaw lies in the dav_xml_get_cdata function's improper handling of whitespace in CDATA sections, allowing a remote attacker to crash the daemon via a specially crafted DAV WRITE request. This vulnerability has a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and requires no authentication, leading to a partial availability impact (daemon crash). Despite its age, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. While there's limited community discussion and media coverage, the vulnerability is not listed on the CISA KEV catalog, suggesting it's not a prevalent threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.27CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.1, < 2.4.9CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
10.1.3.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:10.1.3.5.0:*:*:*:*:*:*:* | ||
11.1.1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:11.1.1.7.0:*:*:*:*:*:*:* | ||
12.1.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:http_server:12.1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_dav denial of service via crafted DAV WRITE request
Oct 3, 2013Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project