CVE-2026-73636·Apache vulnerability
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
- Severity
- high
- Software
- Apache
- Fixed in
- 2.4.69
- Published
- 2026-10-01
Affected versions
From: 2.4.0
Until: 2.4.69
Fixed in: 2.4.69
How to fix this CVE
Upgrade Apache HTTP Server to version 2.4.69 or later to patch the digest authentication credential replay vulnerability in mod_auth_digest. This vulnerability allows attackers positioned between clients and servers to intercept and reuse authentication tokens when AuthDigestNonceLifetime is configured to 0. Immediate patching is recommended for all deployments using digest authentication.
sudo dnf update httpdDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /protected-resource HTTP/1.1.*Authorization: Digest.*response=[a-f0-9]{32}.*nonce=[a-f0-9]+.*nc=00000002WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement ModSecurity rules to detect multiple Digest authentication responses using identical nonce values within short time windows; flag requests with Digest response fields appearing in rapid succession as potential replay attempts and rate-limit or block such traffic.How to check if you are affected
- Check installed Apache version: apachectl -v or httpd -v; verify it is 2.4.69 or later
- Verify if mod_auth_digest is enabled: apache2ctl -M | grep digest_module (Ubuntu/Debian) or httpd -M | grep digest_module (RHEL/CentOS)
- Check Apache configuration for AuthDigestNonceLifetime set to 0: grep -r 'AuthDigestNonceLifetime 0' /etc/apache2/ or /etc/httpd/
- Confirm patch applied by running: dpkg -l | grep apache2 (Debian-based) or rpm -qa | grep httpd (RHEL-based) and verify version is 2.4.69+
FAQ
What is CVE-2026-73636?
CVE-2026-73636 is a credential replay vulnerability in Apache's mod_auth_digest module where improperly configured nonce lifetimes allow network attackers to capture and reuse digest authentication tokens in subsequent requests without valid authentication.
Is CVE-2026-73636 being actively exploited?
No, CVE-2026-73636 is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are currently available, though the vulnerability is network-exploitable and organizations should prioritize patching.
What versions of Apache are affected by CVE-2026-73636?
Apache HTTP Server versions 2.4.0 through 2.4.68 are affected; version 2.4.69 and later contain the fix.
How do I check if my server is vulnerable to CVE-2026-73636?
Run: httpd -v (or apachectl -v on Ubuntu/Debian) to get your version; if it reports 2.4.68 or earlier and mod_auth_digest is enabled (httpd -M | grep digest_module), cross-check your Apache configuration for AuthDigestNonceLifetime set to 0.
Does Defensia detect CVE-2026-73636?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-73636 will appear in your dashboard with remediation steps.
Related Apache CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-73636. Free for 1 server.
Get started free