OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2026-73637

HIGH · CVSS 7.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-05

CyberRota Analysis

AI-Generated

The Apache HTTP Server prior to version 2.4.69 is vulnerable to a use-after-free flaw in the mod_auth_digest module, which can lead to authentication state corruption when concurrent Digest authentication requests are made with specific configurations. This vulnerability allows unauthenticated remote clients to exploit the issue, potentially compromising the integrity of authentication processes. Organizations using affected versions, especially those with AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0, should prioritize upgrading to version 2.4.69 to mitigate the risk.

CVE
CVE-2026-73637
Severity
HIGH
CVSS
7.3
EPSS
0.26%
Apache

Original NVD Description

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)