httpd: httpd: Authentication state corruption via concurrent Digest authentication requests

cve CVE-2026-73637 3 sources, 3 claims · Watch

Red Hat writes:
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsapache_software_foundation/apache_http_server
NVD says “Apache Software Foundation · Apache HTTP Server”
made_byapache_software_foundation
NVD says “Apache Software Foundation”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
GitHub advisories7.3
receipt
Source
GitHub advisories
Its words
7.3
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-73637",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-416",
      "name": "Use After Free"
    }
  ],
  "description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
  "ghsa_id": "GHSA-gr5c-77fq-wx32",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gr5c-77fq-wx32"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-73637"
    }
  ],
  "nvd_published_at": "2026-10-01T17:17:31Z",
  "published_at": "2026-10-01T18:32:46Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
    "https://httpd.apache.org/security/vulnerabilities_24.html",
    "http://www.openwall.com/lists/oss-security/2026/10/01/28",
    "https://github.com/advisories/GHSA-gr5c-77fq-wx32"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:58Z",
  "url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
conflict
NVD7.3
receipt
Source
NVD
Its words
7.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache HTTP Server",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.4.68",
                "status": "affected",
                "version": "2.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
      }
    ],
    "id": "CVE-2026-73637",
    "lastModified": "2026-10-01T21:17:24.467",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-73637",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:42:16.346387Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T17:17:31.000",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat5.6
receipt
Source
Red Hat
Its words
5.6
Read by
field:cvss3_score
Said since
2026-10-02 18:04 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-73637",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:74858"
  ],
  "affected_packages": [
    "httpd-main-2.4.69-1.hum1"
  ],
  "bugzilla": "2544814",
  "bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
  "cvss3_score": "5.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T16:18:30Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
  "severity": "moderate"
}
—
Cwe
cwe
not compared
GitHub advisoriesCWE-416
receipt
Source
GitHub advisories
Its words
CWE-416
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-73637",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-416",
      "name": "Use After Free"
    }
  ],
  "description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
  "ghsa_id": "GHSA-gr5c-77fq-wx32",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gr5c-77fq-wx32"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-73637"
    }
  ],
  "nvd_published_at": "2026-10-01T17:17:31Z",
  "published_at": "2026-10-01T18:32:46Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
    "https://httpd.apache.org/security/vulnerabilities_24.html",
    "http://www.openwall.com/lists/oss-security/2026/10/01/28",
    "https://github.com/advisories/GHSA-gr5c-77fq-wx32"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:58Z",
  "url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cwe
cwe
not compared
Red HatCWE-825
receipt
Source
Red Hat
Its words
CWE-825
Read by
field:CWE
Said since
2026-10-02 18:04 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-73637",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:74858"
  ],
  "affected_packages": [
    "httpd-main-2.4.69-1.hum1"
  ],
  "bugzilla": "2544814",
  "bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
  "cvss3_score": "5.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T16:18:30Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
  "severity": "moderate"
}
—
Packages
packages
Red Hathttpd-main-2.4.69-1.hum1
receipt
Source
Red Hat
Its words
httpd-main-2.4.69-1.hum1
Read by
field:affected_packages[]
Said since
2026-10-02 18:04 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-73637",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:74858"
  ],
  "affected_packages": [
    "httpd-main-2.4.69-1.hum1"
  ],
  "bugzilla": "2544814",
  "bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
  "cvss3_score": "5.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T16:18:30Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
  "severity": "moderate"
}
—
Product
product
NVDApache HTTP Server
receipt
Source
NVD
Its words
Apache HTTP Server
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache HTTP Server",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.4.68",
                "status": "affected",
                "version": "2.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
      }
    ],
    "id": "CVE-2026-73637",
    "lastModified": "2026-10-01T21:17:24.467",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-73637",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:42:16.346387Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T17:17:31.000",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-05 12:22 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-73637",
  "cvss": {
    "score": 7.3,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 7.3,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-416",
      "name": "Use After Free"
    }
  ],
  "description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
  "ghsa_id": "GHSA-gr5c-77fq-wx32",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-gr5c-77fq-wx32"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-73637"
    }
  ],
  "nvd_published_at": "2026-10-01T17:17:31Z",
  "published_at": "2026-10-01T18:32:46Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
    "https://httpd.apache.org/security/vulnerabilities_24.html",
    "http://www.openwall.com/lists/oss-security/2026/10/01/28",
    "https://github.com/advisories/GHSA-gr5c-77fq-wx32"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T21:33:58Z",
  "url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-02 18:04 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-73637",
  "CWE": "CWE-825",
  "advisories": [
    "RHSA-2026:74858"
  ],
  "affected_packages": [
    "httpd-main-2.4.69-1.hum1"
  ],
  "bugzilla": "2544814",
  "bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
  "cvss3_score": "5.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T16:18:30Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
  "severity": "moderate"
}
medium
Status
status
NVDAwaiting Analysis
receipt
Source
NVD
Its words
Awaiting Analysis
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache HTTP Server",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.4.68",
                "status": "affected",
                "version": "2.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
      }
    ],
    "id": "CVE-2026-73637",
    "lastModified": "2026-10-01T21:17:24.467",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-73637",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:42:16.346387Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T17:17:31.000",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-05 12:24 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache HTTP Server",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "2.4.68",
                "status": "affected",
                "version": "2.4.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
      }
    ],
    "id": "CVE-2026-73637",
    "lastModified": "2026-10-01T21:17:24.467",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 3.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-73637",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:42:16.346387Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T17:17:31.000",
    "references": [
      {
        "source": "security@apache.org",
        "url": "https://httpd.apache.org/security/vulnerabilities_24.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Awaiting Analysis",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-416"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
zetlyn/cve-redhat · 2026-10-01
cvss 5.6 cwe CWE-825 packages httpd-main-2.4.69-1.hum1 severity moderate source
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
zetlyn/cve-nvd · 2026-10-01
cvss 7.3 product Apache HTTP Server status Awaiting Analysis vendor Apache Software Foundation source
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...
zetlyn/cve-ghsa · 2026-10-01
cvss 7.3 cwe CWE-416 severity high source