CVE-2026-73636: 
Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-73636 is an authentication bypass by capture-replay vulnerability in the mod_auth_digest module of Apache HTTP Server 2.4.x. It allows a man-in-the-middle (MITM) attacker to replay captured HTTP Digest authentication credentials by crafting requests that trigger garbage collection of the client's shared memory entry, but only when AuthDigestNonceLifetime is set to 0. All platforms running Apache HTTP Server versions 2.4.0 through 2.4.68 are affected. The vulnerability was published on October 1, 2026, with a fix available in version 2.4.69. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-294 (Authentication Bypass by Capture-replay), residing in Apache's mod_auth_digest module. When AuthDigestNonceLifetime is configured to 0 (meaning nonces do not expire), an attacker positioned as a MITM can intercept valid HTTP Digest authentication credentials from a legitimate client. By crafting specific requests that trigger garbage collection of the client's shared memory entry in the server, the attacker can then replay the captured credentials to authenticate as that client. The attack requires network-level positioning (MITM) and the specific non-default configuration of AuthDigestNonceLifetime=0, making it a high-complexity but unauthenticated attack vector (GitHub Advisory, Apache Vulnerabilities).

Impact

Successful exploitation allows an unauthenticated attacker to bypass HTTP Digest authentication and gain unauthorized access to resources protected by mod_auth_digest. The CVSS assessment indicates high impacts to confidentiality, integrity, and availability, meaning an attacker could read sensitive data, modify content, and potentially disrupt service on the affected server. The scope is limited to the affected Apache HTTP Server instance, but unauthorized access could serve as a foothold for further lateral movement within the environment (GitHub Advisory, Feedly).

Exploitability

As of the disclosure date (October 1, 2026), there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the NVD SSVC assessment classifies exploitation as "none" at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a MITM network position and the specific non-default configuration of AuthDigestNonceLifetime=0, which limits the practical attack surface.

Exploitation steps

  1. Reconnaissance: Identify Apache HTTP Server instances (versions 2.4.0–2.4.68) that use HTTP Digest authentication (mod_auth_digest) with AuthDigestNonceLifetime set to 0. This can be done by probing HTTP responses for WWW-Authenticate: Digest headers.
  2. Network Positioning: Establish a man-in-the-middle position on the network path between a legitimate client and the target Apache server (e.g., via ARP spoofing, DNS poisoning, or rogue access point).
  3. Credential Capture: Intercept and record a valid HTTP Digest authentication exchange from a legitimate client, capturing the Authorization header containing the digest response, username, nonce, and other parameters.
  4. Trigger Garbage Collection: Send crafted HTTP requests to the Apache server designed to trigger garbage collection of the legitimate client's shared memory entry in mod_auth_digest, invalidating the server's tracking of the used nonce.
  5. Replay Attack: Replay the previously captured Authorization header in a new request to the protected resource. Because the shared memory entry has been garbage-collected, the server no longer recognizes the nonce as used and accepts the replayed credentials, granting unauthorized access (GitHub Advisory, Apache Vulnerabilities).

Indicators of compromise

  • Network: Repeated HTTP requests to Digest-authenticated endpoints from an IP address that does not match the original authenticating client; duplicate Authorization: Digest headers with identical nonce values appearing from different source IPs.
  • Logs: Apache access logs showing successful authentication (HTTP 200) for the same nonce value used by multiple distinct client IPs in a short time window; unusual patterns of requests that precede successful authentication without a corresponding initial authentication handshake.
  • Process/Memory: Abnormal frequency of shared memory garbage collection events in mod_auth_digest debug logs, which may indicate crafted requests designed to trigger the vulnerable code path.

Mitigation and workarounds

The primary remediation is to upgrade Apache HTTP Server to version 2.4.69 or later, which contains the fix for this vulnerability (GitHub Advisory, Apache Vulnerabilities). If immediate patching is not feasible, avoid setting AuthDigestNonceLifetime to 0 in the Apache configuration — using any non-zero value eliminates the specific precondition required for exploitation. Additionally, deploying TLS/HTTPS to encrypt traffic between clients and the server will prevent MITM attackers from capturing Digest authentication credentials in the first place, effectively neutralizing the attack vector.

Community reactions

The vulnerability was noted on the OSS-Security mailing list shortly after disclosure and referenced in the Apache announcement mailing list (OSS-Sec, Apache Announce). A brief mention appeared on Bluesky in the infosec community. Overall community reaction has been measured, reflecting the limited exploitability due to the non-default configuration requirement and the absence of public exploit code.

Additional resources


Source: This report was generated using AI

Related Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93546HIGH8.8
  • Apache HTTP Server logoApache HTTP Server
  • cpe:2.3:a:apache:http_server
NoYesOct 01, 2026
CVE-2026-73636HIGH8.1
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_proxy_html
NoYesOct 01, 2026
CVE-2026-63718HIGH7.5
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::httpd-manual
NoYesOct 01, 2026
CVE-2026-73637HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd
NoYesOct 01, 2026
CVE-2026-79768MEDIUM5.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_session
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management