CVE-2026-73637: 
Apache HTTP Server vulnerability analysis and mitigation

Overview

CVE-2026-73637 is a use-after-free vulnerability in the mod_auth_digest module of Apache HTTP Server that allows unauthenticated remote attackers to corrupt authentication state. It affects Apache HTTP Server versions 2.4.0 through 2.4.68 on all platforms, and is triggered when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. The vulnerability was disclosed on October 1, 2026, with a patch available in version 2.4.69. It carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Apache Advisory).

Technical details

The root cause is a use-after-free condition (CWE-416) in the mod_auth_digest module, where memory associated with authentication state is freed and subsequently referenced during concurrent Digest authentication request processing. The vulnerability is exploitable remotely over the network with no authentication or user interaction required, making it automatable. Exploitation requires the server to be configured with either AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0 — both non-default but documented configuration options. No public proof-of-concept code has been identified at this time (GitHub Advisory, Apache Advisory).

Impact

Successful exploitation can result in authentication state corruption, potentially enabling authentication bypass or causing authentication failures for legitimate users. The vulnerability has partial impacts across confidentiality, integrity, and availability — an attacker may gain unauthorized access to protected resources, manipulate authentication outcomes, or disrupt the authentication service. The scope is limited to the affected server instance, with no evidence of lateral movement potential beyond authentication context corruption (GitHub Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date. The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable due to its network-accessible, unauthenticated nature. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on specific non-default server configurations (AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0) (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Apache HTTP Server to version 2.4.69 or later, which resolves the use-after-free condition in mod_auth_digest. As a temporary workaround, administrators can disable AuthDigestNcCheck and ensure AuthDigestNonceLifetime is not set to 0 in their configuration, which removes the preconditions required for exploitation — though this may reduce the security properties of Digest authentication. Organizations not using mod_auth_digest are not affected and should confirm the module is disabled (GitHub Advisory, Apache Advisory).

Additional resources


Source: This report was generated using AI

Related Apache HTTP Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93546HIGH8.8
  • Apache HTTP Server logoApache HTTP Server
  • cpe:2.3:a:apache:http_server
NoYesOct 01, 2026
CVE-2026-73636HIGH8.1
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_proxy_html
NoYesOct 01, 2026
CVE-2026-63718HIGH7.5
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::httpd-manual
NoYesOct 01, 2026
CVE-2026-73637HIGH7.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd
NoYesOct 01, 2026
CVE-2026-79768MEDIUM5.3
  • Apache HTTP Server logoApache HTTP Server
  • httpd:2.4::mod_session
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management