Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-73636

2 дня назад

A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-73636

2 дня назад

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-73636

2 дня назад

Authentication bypass by capture-replay in mod_auth_digest in Apache S ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-x3h4-7828-fv9v

2 дня назад

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-73636

A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.

CVSS3: 8.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-73636

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVSS3: 8.1
0%
Низкий
2 дня назад
debian логотип
CVE-2026-73636

Authentication bypass by capture-replay in mod_auth_digest in Apache S ...

CVSS3: 8.1
0%
Низкий
2 дня назад
github логотип
GHSA-x3h4-7828-fv9v

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

CVSS3: 8.1
0%
Низкий
2 дня назад

Уязвимостей на страницу