high CVSS 8.1

CVE-2026-73636·Apache vulnerability

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Severity
high
Software
Apache
Fixed in
2.4.69
Published
2026-10-01

Affected versions

From: 2.4.0

Until: 2.4.69

Fixed in: 2.4.69

How to fix this CVE

Upgrade Apache HTTP Server to version 2.4.69 or later to patch the digest authentication credential replay vulnerability in mod_auth_digest. This vulnerability allows attackers positioned between clients and servers to intercept and reuse authentication tokens when AuthDigestNonceLifetime is configured to 0. Immediate patching is recommended for all deployments using digest authentication.

sudo dnf update httpd

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET /protected-resource HTTP/1.1.*Authorization: Digest.*response=[a-f0-9]{32}.*nonce=[a-f0-9]+.*nc=00000002

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement ModSecurity rules to detect multiple Digest authentication responses using identical nonce values within short time windows; flag requests with Digest response fields appearing in rapid succession as potential replay attempts and rate-limit or block such traffic.

How to check if you are affected

  1. Check installed Apache version: apachectl -v or httpd -v; verify it is 2.4.69 or later
  2. Verify if mod_auth_digest is enabled: apache2ctl -M | grep digest_module (Ubuntu/Debian) or httpd -M | grep digest_module (RHEL/CentOS)
  3. Check Apache configuration for AuthDigestNonceLifetime set to 0: grep -r 'AuthDigestNonceLifetime 0' /etc/apache2/ or /etc/httpd/
  4. Confirm patch applied by running: dpkg -l | grep apache2 (Debian-based) or rpm -qa | grep httpd (RHEL-based) and verify version is 2.4.69+

FAQ

What is CVE-2026-73636?

CVE-2026-73636 is a credential replay vulnerability in Apache's mod_auth_digest module where improperly configured nonce lifetimes allow network attackers to capture and reuse digest authentication tokens in subsequent requests without valid authentication.

Is CVE-2026-73636 being actively exploited?

No, CVE-2026-73636 is not listed in CISA's Known Exploited Vulnerabilities catalog and no public exploits are currently available, though the vulnerability is network-exploitable and organizations should prioritize patching.

What versions of Apache are affected by CVE-2026-73636?

Apache HTTP Server versions 2.4.0 through 2.4.68 are affected; version 2.4.69 and later contain the fix.

How do I check if my server is vulnerable to CVE-2026-73636?

Run: httpd -v (or apachectl -v on Ubuntu/Debian) to get your version; if it reports 2.4.68 or earlier and mod_auth_digest is enabled (httpd -M | grep digest_module), cross-check your Apache configuration for AuthDigestNonceLifetime set to 0.

Does Defensia detect CVE-2026-73636?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Apache is installed on a monitored server, CVE-2026-73636 will appear in your dashboard with remediation steps.

Related Apache CVEs

CVE-2021-41773CVSS 10A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions. The fix in Apache HTTP Server 2.4.50 was found to be incomplete, see CVE-2021-42013.
CVE-2021-42013CVSS 10It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.
CVE-2024-38474CVSS 9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
CVE-2026-57941CVSS 9.8Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVE-2024-38476CVSS 9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-73636. Free for 1 server.

Get started free