httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
cve CVE-2026-73637 3 sources, 3 claims · Watch
Red Hat writes:
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests the claim
httpd: httpd: Authentication state corruption via concurrent Digest authentication requests the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | apache_software_foundation/apache_http_serverNVD says “Apache Software Foundation · Apache HTTP Server” |
| made_by | apache_software_foundationNVD says “Apache Software Foundation” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss conflict | GitHub advisories | 7.3receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-73637",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-416",
"name": "Use After Free"
}
],
"description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
"ghsa_id": "GHSA-gr5c-77fq-wx32",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gr5c-77fq-wx32"
},
{
"type": "CVE",
"value": "CVE-2026-73637"
}
],
"nvd_published_at": "2026-10-01T17:17:31Z",
"published_at": "2026-10-01T18:32:46Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
"https://httpd.apache.org/security/vulnerabilities_24.html",
"http://www.openwall.com/lists/oss-security/2026/10/01/28",
"https://github.com/advisories/GHSA-gr5c-77fq-wx32"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
"type": "unreviewed",
"updated_at": "2026-10-01T21:33:58Z",
"url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cvss cvss conflict | NVD | 7.3receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Apache HTTP Server",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.4.68",
"status": "affected",
"version": "2.4.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
}
],
"id": "CVE-2026-73637",
"lastModified": "2026-10-01T21:17:24.467",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-73637",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:42:16.346387Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T17:17:31.000",
"references": [
{
"source": "security@apache.org",
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss conflict | Red Hat | 5.6receipt
What the source handed over{
"CVE": "CVE-2026-73637",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:74858"
],
"affected_packages": [
"httpd-main-2.4.69-1.hum1"
],
"bugzilla": "2544814",
"bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
"cvss3_score": "5.6",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T16:18:30Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
"severity": "moderate"
} | — |
| Cwe cwe not compared | GitHub advisories | CWE-416receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-73637",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-416",
"name": "Use After Free"
}
],
"description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
"ghsa_id": "GHSA-gr5c-77fq-wx32",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gr5c-77fq-wx32"
},
{
"type": "CVE",
"value": "CVE-2026-73637"
}
],
"nvd_published_at": "2026-10-01T17:17:31Z",
"published_at": "2026-10-01T18:32:46Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
"https://httpd.apache.org/security/vulnerabilities_24.html",
"http://www.openwall.com/lists/oss-security/2026/10/01/28",
"https://github.com/advisories/GHSA-gr5c-77fq-wx32"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
"type": "unreviewed",
"updated_at": "2026-10-01T21:33:58Z",
"url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cwe cwe not compared | Red Hat | CWE-825receipt
What the source handed over{
"CVE": "CVE-2026-73637",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:74858"
],
"affected_packages": [
"httpd-main-2.4.69-1.hum1"
],
"bugzilla": "2544814",
"bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
"cvss3_score": "5.6",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T16:18:30Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
"severity": "moderate"
} | — |
| Packages packages | Red Hat | httpd-main-2.4.69-1.hum1receipt
What the source handed over{
"CVE": "CVE-2026-73637",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:74858"
],
"affected_packages": [
"httpd-main-2.4.69-1.hum1"
],
"bugzilla": "2544814",
"bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
"cvss3_score": "5.6",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T16:18:30Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
"severity": "moderate"
} | — |
| Product product | NVD | Apache HTTP Serverreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Apache HTTP Server",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.4.68",
"status": "affected",
"version": "2.4.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
}
],
"id": "CVE-2026-73637",
"lastModified": "2026-10-01T21:17:24.467",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-73637",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:42:16.346387Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T17:17:31.000",
"references": [
{
"source": "security@apache.org",
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — |
| Severity severity conflict | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-73637",
"cvss": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-416",
"name": "Use After Free"
}
],
"description": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.",
"ghsa_id": "GHSA-gr5c-77fq-wx32",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-gr5c-77fq-wx32",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-gr5c-77fq-wx32"
},
{
"type": "CVE",
"value": "CVE-2026-73637"
}
],
"nvd_published_at": "2026-10-01T17:17:31Z",
"published_at": "2026-10-01T18:32:46Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-73637",
"https://httpd.apache.org/security/vulnerabilities_24.html",
"http://www.openwall.com/lists/oss-security/2026/10/01/28",
"https://github.com/advisories/GHSA-gr5c-77fq-wx32"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69...",
"type": "unreviewed",
"updated_at": "2026-10-01T21:33:58Z",
"url": "https://api.github.com/advisories/GHSA-gr5c-77fq-wx32",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Severity severity conflict | Red Hat | moderate A flaw that is harder to exploit, or whose impact is limited. receipt
What the source handed over{
"CVE": "CVE-2026-73637",
"CWE": "CWE-825",
"advisories": [
"RHSA-2026:74858"
],
"affected_packages": [
"httpd-main-2.4.69-1.hum1"
],
"bugzilla": "2544814",
"bugzilla_description": "httpd: httpd: Authentication state corruption via concurrent Digest authentication requests",
"cvss3_score": "5.6",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T16:18:30Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-73637.json",
"severity": "moderate"
} | medium |
| Status status | NVD | Awaiting Analysisreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Apache HTTP Server",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.4.68",
"status": "affected",
"version": "2.4.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
}
],
"id": "CVE-2026-73637",
"lastModified": "2026-10-01T21:17:24.467",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-73637",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:42:16.346387Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T17:17:31.000",
"references": [
{
"source": "security@apache.org",
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Apache Software Foundationreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "Apache HTTP Server",
"vendor": "Apache Software Foundation",
"versions": [
{
"lessThanOrEqual": "2.4.68",
"status": "affected",
"version": "2.4.0",
"versionType": "semver"
}
]
}
],
"source": "security@apache.org"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."
}
],
"id": "CVE-2026-73637",
"lastModified": "2026-10-01T21:17:24.467",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-73637",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:42:16.346387Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T17:17:31.000",
"references": [
{
"source": "security@apache.org",
"url": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"source": "af854a3a-2127-422b-91ae-364da2661108",
"url": "http://www.openwall.com/lists/oss-security/2026/10/01/28"
}
],
"sourceIdentifier": "security@apache.org",
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-416"
}
],
"source": "security@apache.org",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| httpd: httpd: Authentication state corruption via concurrent Digest authentication requests zetlyn/cve-redhat · 2026-10-01 | cvss 5.6 cwe CWE-825 packages httpd-main-2.4.69-1.hum1 severity moderate | source |
| Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.
Users are recommended to upgrade to version 2.4.69, which fixes this issue. zetlyn/cve-nvd · 2026-10-01 | cvss 7.3 product Apache HTTP Server status Awaiting Analysis vendor Apache Software Foundation | source |
| Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69... zetlyn/cve-ghsa · 2026-10-01 | cvss 7.3 cwe CWE-416 severity high | source |