CVE-2018-11803: Apache Subversion

High severity, CVSS 7.5. EPSS: 58.5% chance of exploitation in the next 30 days.

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.

Affected products

  • Apache Subversion: from 1.10.0, up to and including 1.10.3; version 1.11.0 only
  • Canonical Ubuntu Linux: version 18.10 only

Published 2019-02-05. Last modified 2026-06-17.