Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-73636

Опубликовано: 01 окт. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.

Users are recommended to upgrade to version 2.4.69, which fixes this issue.

EPSS

Процентиль: 28%
0.00368
Низкий

8.1 High

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 8.1
redhat
2 дня назад

A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.

CVSS3: 8.1
debian
2 дня назад

Authentication bypass by capture-replay in mod_auth_digest in Apache S ...

CVSS3: 8.1
github
2 дня назад

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

EPSS

Процентиль: 28%
0.00368
Низкий

8.1 High

CVSS3

Дефекты

CWE-294
Уязвимость CVE-2026-73636