{"api_version":"1","generated_at":"2026-10-01T21:51:01+00:00","cve":"CVE-2026-73636","urls":{"html":"https://cve.report/CVE-2026-73636","api":"https://cve.report/api/cve/CVE-2026-73636.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73636","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636"},"summary":{"title":"Apache HTTP Server: mod_auth_digest one-time-nonce replay attack","description":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-10-01 17:17:30","updated_at":"2026-10-01 21:17:24"},"problem_types":["CWE-294","CWE-294 CWE-294 Authentication Bypass by Capture-replay"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}}],"references":[{"url":"https://httpd.apache.org/security/vulnerabilities_24.html","name":"https://httpd.apache.org/security/vulnerabilities_24.html","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/27","name":"http://www.openwall.com/lists/oss-security/2026/10/01/27","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73636","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73636","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache HTTP Server","version":"affected 2.4.0 2.4.68 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-06-08T01:36:00.000Z","lang":"en","value":"Report received"},{"source":"CNA","time":"2026-10-01T12:00:00.000Z","lang":"en","value":"fixed in 2.4.x by r1937721"},{"source":"CNA","time":"2026-10-01T12:00:00.000Z","lang":"eng","value":"2.4.69 released"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Hyojae Lee","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-73636","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-10-01T19:43:35.472082Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-01T19:43:38.554Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-10-01T20:09:33.050Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/10/01/27"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache HTTP Server","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.4.68","status":"affected","version":"2.4.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Hyojae Lee"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.<br><br>Users are recommended to upgrade to version 2.4.69, which fixes this issue."}],"value":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue."}],"metrics":[{"other":{"content":{"text":"low"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-294","description":"CWE-294 Authentication Bypass by Capture-replay","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T16:17:59.618Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://httpd.apache.org/security/vulnerabilities_24.html"}],"source":{"discovery":"UNKNOWN"},"timeline":[{"lang":"en","time":"2026-06-08T01:36:00.000Z","value":"Report received"},{"lang":"en","time":"2026-10-01T12:00:00.000Z","value":"fixed in 2.4.x by r1937721"},{"lang":"eng","time":"2026-10-01T12:00:00.000Z","value":"2.4.69 released"}],"title":"Apache HTTP Server: mod_auth_digest one-time-nonce replay attack","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-73636","datePublished":"2026-10-01T16:17:59.618Z","dateReserved":"2026-08-13T12:47:45.798Z","dateUpdated":"2026-10-01T20:09:33.050Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 17:17:30","lastModifiedDate":"2026-10-01 21:17:24","problem_types":["CWE-294","CWE-294 CWE-294 Authentication Bypass by Capture-replay"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-01T19:43:35.472082Z","id":"CVE-2026-73636","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73636","Ordinal":"1","Title":"Apache HTTP Server: mod_auth_digest one-time-nonce replay attack","CVE":"CVE-2026-73636","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73636","Ordinal":"1","NoteData":"Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.","Type":"Description","Title":"Apache HTTP Server: mod_auth_digest one-time-nonce replay attack"}]}}}