
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73636 is an authentication bypass by capture-replay vulnerability in the mod_auth_digest module of Apache HTTP Server 2.4.x. It allows a man-in-the-middle (MITM) attacker to replay captured HTTP Digest authentication credentials by crafting requests that trigger garbage collection of the client's shared memory entry, but only when AuthDigestNonceLifetime is set to 0. All platforms running Apache HTTP Server versions 2.4.0 through 2.4.68 are affected. The vulnerability was published on October 1, 2026, with a fix available in version 2.4.69. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Feedly).
The root cause is classified as CWE-294 (Authentication Bypass by Capture-replay), residing in Apache's mod_auth_digest module. When AuthDigestNonceLifetime is configured to 0 (meaning nonces do not expire), an attacker positioned as a MITM can intercept valid HTTP Digest authentication credentials from a legitimate client. By crafting specific requests that trigger garbage collection of the client's shared memory entry in the server, the attacker can then replay the captured credentials to authenticate as that client. The attack requires network-level positioning (MITM) and the specific non-default configuration of AuthDigestNonceLifetime=0, making it a high-complexity but unauthenticated attack vector (GitHub Advisory, Apache Vulnerabilities).
Successful exploitation allows an unauthenticated attacker to bypass HTTP Digest authentication and gain unauthorized access to resources protected by mod_auth_digest. The CVSS assessment indicates high impacts to confidentiality, integrity, and availability, meaning an attacker could read sensitive data, modify content, and potentially disrupt service on the affected server. The scope is limited to the affected Apache HTTP Server instance, but unauthorized access could serve as a foothold for further lateral movement within the environment (GitHub Advisory, Feedly).
As of the disclosure date (October 1, 2026), there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (Feedly). The EPSS score is reported as 0.0, and the NVD SSVC assessment classifies exploitation as "none" at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a MITM network position and the specific non-default configuration of AuthDigestNonceLifetime=0, which limits the practical attack surface.
mod_auth_digest) with AuthDigestNonceLifetime set to 0. This can be done by probing HTTP responses for WWW-Authenticate: Digest headers.Authorization header containing the digest response, username, nonce, and other parameters.mod_auth_digest, invalidating the server's tracking of the used nonce.Authorization header in a new request to the protected resource. Because the shared memory entry has been garbage-collected, the server no longer recognizes the nonce as used and accepts the replayed credentials, granting unauthorized access (GitHub Advisory, Apache Vulnerabilities).Authorization: Digest headers with identical nonce values appearing from different source IPs.mod_auth_digest debug logs, which may indicate crafted requests designed to trigger the vulnerable code path.The primary remediation is to upgrade Apache HTTP Server to version 2.4.69 or later, which contains the fix for this vulnerability (GitHub Advisory, Apache Vulnerabilities). If immediate patching is not feasible, avoid setting AuthDigestNonceLifetime to 0 in the Apache configuration — using any non-zero value eliminates the specific precondition required for exploitation. Additionally, deploying TLS/HTTPS to encrypt traffic between clients and the server will prevent MITM attackers from capturing Digest authentication credentials in the first place, effectively neutralizing the attack vector.
The vulnerability was noted on the OSS-Security mailing list shortly after disclosure and referenced in the Apache announcement mailing list (OSS-Sec, Apache Announce). A brief mention appeared on Bluesky in the infosec community. Overall community reaction has been measured, reflecting the limited exploitability due to the non-default configuration requirement and the absence of public exploit code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."