CVE-2026-48005·Apache vulnerability
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to patch the authentication bypass vulnerability in mod_auth_digest. This update eliminates the weakness that allows attackers to forge digest authentication headers and trigger service disruption. If you are currently running versions 2.4.0 through 2.4.68 with Digest authentication enabled, immediate patching is recommended to restore proper authentication validation.
sudo dnf update httpd httpd-toolsDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /.*HTTP.*Authorization:.*Digest.*nc=([0-9a-fA-F]+).*qop=auth|Multiple 401 responses to same endpoint from same source IP within 60 seconds|Authorization header with mismatched nonce value in repeated requestsWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule to rate-limit or block requests from single IPs sending multiple Authorization headers with varying digest values within a short timeframe. Alternatively, block requests with malformed or duplicate Digest authentication parameters.How to check if you are affected
- Check Apache version: apache2ctl -v or httpd -v — confirm installed version is 2.4.68 or earlier
- Verify Digest authentication is enabled: grep -i 'AuthDigestNcCheck' /etc/apache2/mods-enabled/*.conf or /etc/httpd/conf.d/*.conf
- Search access and error logs for repeated 401 responses from single IP: grep '401' /var/log/apache2/access.log | cut -d' ' -f1 | sort | uniq -c | sort -rn
- Confirm patch applied: apache2ctl -v or httpd -v should show 2.4.69 or later after upgrade completion
FAQ
What is CVE-2026-48005?
CVE-2026-48005 is an authentication bypass vulnerability in Apache mod_auth_digest that allows unauthenticated remote attackers to craft forged Authorization headers and force legitimate users to re-authenticate, causing a denial of service when AuthDigestNcCheck is enabled.
Is CVE-2026-48005 being actively exploited?
No, CVE-2026-48005 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit code is currently available. However, the vulnerability is straightforward to exploit and should still be patched promptly.
What versions of Apache are affected by CVE-2026-48005?
Apache HTTP Server versions 2.4.0 through 2.4.68 are vulnerable. Version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-48005?
Run 'httpd -v' or 'apache2ctl -v' and verify the version number. If it shows 2.4.68 or earlier and Digest authentication is enabled (check 'grep AuthDigest /etc/httpd/conf.d/*.conf'), your server is vulnerable.
Does Defensia detect CVE-2026-48005?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-48005 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-48005. Free for 1 server.
Get started free