Количество 4
Количество 4
CVE-2026-73636
A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.
CVE-2026-73636
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVE-2026-73636
Authentication bypass by capture-replay in mod_auth_digest in Apache S ...
GHSA-x3h4-7828-fv9v
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-73636 A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials. | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
CVE-2026-73636 Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
CVE-2026-73636 Authentication bypass by capture-replay in mod_auth_digest in Apache S ... | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
GHSA-x3h4-7828-fv9v Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue. | CVSS3: 8.1 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу