Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache HTTP Server: authentication bypass

High8.1CVE-2026-73636 · Published Oct 1, 2026 · updated Oct 5, 2026

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
>= 2.4.0, <= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1
Apache HTTP Server: out-of-bounds write
High7.5Oct 1