CVE-2015-0202: Apache Subversion
High severity, CVSS 7.8. EPSS: 8% chance of exploitation in the next 30 days.
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.
Affected products
- Apache Subversion: version 1.8.0 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …
- Opensuse Opensuse: version 13.1 only; version 13.2 only
Published 2015-04-08. Last modified 2026-06-17.