Missing Authentication for Critical Function in Apache HTTP Server - CVE-2026-48005
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service through forced re-authentication.
The vulnerability exists due to missing authentication checks in mod_auth_digest when processing forged Authorization headers. A remote attacker can send forged Authorization headers to cause a denial of service through forced re-authentication.
Digest authentication must be enabled with AuthDigestNcCheck.