Authentication Bypass by Capture-replay in Apache HTTP Server - CVE-2026-73636
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper handling of one-time nonces in mod_auth_digest when AuthDigestNonceLifetime is set to 0. A remote attacker can replay captured digest authentication credentials in crafted requests that trigger garbage collection of the client's shared-memory entry to bypass authentication.
Exploitation requires a man-in-the-middle position.