
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73637 is a use-after-free vulnerability in the mod_auth_digest module of Apache HTTP Server that allows unauthenticated remote attackers to corrupt authentication state. It affects Apache HTTP Server versions 2.4.0 through 2.4.68 on all platforms, and is triggered when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. The vulnerability was disclosed on October 1, 2026, with a patch available in version 2.4.69. It carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, Apache Advisory).
The root cause is a use-after-free condition (CWE-416) in the mod_auth_digest module, where memory associated with authentication state is freed and subsequently referenced during concurrent Digest authentication request processing. The vulnerability is exploitable remotely over the network with no authentication or user interaction required, making it automatable. Exploitation requires the server to be configured with either AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0 — both non-default but documented configuration options. No public proof-of-concept code has been identified at this time (GitHub Advisory, Apache Advisory).
Successful exploitation can result in authentication state corruption, potentially enabling authentication bypass or causing authentication failures for legitimate users. The vulnerability has partial impacts across confidentiality, integrity, and availability — an attacker may gain unauthorized access to protected resources, manipulate authentication outcomes, or disrupt the authentication service. The scope is limited to the affected server instance, with no evidence of lateral movement potential beyond authentication context corruption (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date. The NVD SSVC assessment classifies exploitation as "none" at this time, though the attack is rated as automatable due to its network-accessible, unauthenticated nature. The EPSS score is reported as 0.0, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on specific non-default server configurations (AuthDigestNcCheck enabled or AuthDigestNonceLifetime set to 0) (GitHub Advisory).
The primary remediation is to upgrade Apache HTTP Server to version 2.4.69 or later, which resolves the use-after-free condition in mod_auth_digest. As a temporary workaround, administrators can disable AuthDigestNcCheck and ensure AuthDigestNonceLifetime is not set to 0 in their configuration, which removes the preconditions required for exploitation — though this may reduce the security properties of Digest authentication. Organizations not using mod_auth_digest are not affected and should confirm the module is disabled (GitHub Advisory, Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."