Apache Software FoundationCVE-2026-73637
Apache HTTP Server: use after free
High7.3CVE-2026-73637 · Published Oct 1, 2026 · updated Oct 5, 2026
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache HTTP Server Product | >= 2.4.0, <= 2.4.68 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-416
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Apache HTTP Server: integer overflow | High8.8 | No fix yet |
| Oct 1 | Path equivalence: '/./' | Medium5.3 | No fix yet |
| Oct 1 | Apache HTTP Server: request smuggling | High7.5 | No fix yet |
| Oct 1 | Apache HTTP Server: authentication bypass | High8.1 | No fix yet |
| Oct 1 | Apache HTTP Server: exposed files | Medium5.3 | No fix yet |
| Oct 1 | Apache HTTP Server: out-of-bounds write | High7.5 | No fix yet |