Summary
CVE-2026-55509 is a blind SQL injection vulnerability in the sample MySQLBrowserProvider shipped with WsgiDAV, a WSGI-based WebDAV server. Versions prior to 4.3.5 concatenate a URL-derived record key directly into SQL WHERE clauses without sanitization, allowing an unauthenticated attacker to extract data from the backing MySQL database. The issue is rated HIGH severity (8.8) but only affects deployments that have explicitly enabled this non-default sample provider.
Technical details
- Root cause: The
_exists_record_by_primary_key,_get_field_by_primary_key, and_get_record_by_primary_keymethods in the sample MySQL DAV provider build SQL queries by directly concatenating a record key parsed from the request URL, with no escaping or parameterization. - Trigger conditions: The vulnerable provider must be explicitly configured and enabled as the DAV backend; it is not active in a default WsgiDAV installation.
- Attack vector: Network-based, unauthenticated. A crafted path such as
/db/users/0' OR '1'='1injected into a standard WebDAV GET request manipulates the underlying SQL query. - Impact: The application returns different HTTP status codes (e.g., 500 vs. 404) depending on whether the injected condition is true, creating a status-code oracle. This allows attackers to extract arbitrary data reachable by the configured MySQL account, and potentially modify data if that account has write privileges.
Affected software
- WsgiDAV versions prior to 4.3.5, specifically deployments that have enabled the sample
mysql_dav_provider(MySQLBrowserProvider) module. - Fixed in WsgiDAV 4.3.5 (released 2026-06-27).
Severity
CVSS v4.0 Base Score: 8.8 (High)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade WsgiDAV to version 4.3.5 or later.
- If patching is not immediately possible: Disable or remove the
MySQLBrowserProvidersample module from the WsgiDAV configuration if it has been enabled; restrict network access to any WsgiDAV instance exposing this provider; audit MySQL account permissions used by the provider to limit data exposure and prevent write access.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Rendered/raw response body: a link to
https://github.com/mar10/wsgidav/followed by text readingWsgiDAV/<version> - The
generatormeta tag’s content:WsgiDAV/<version> - Page title: text beginning with
WsgiDAV - Index of

