CVE-2026-48005 is a vulnerability in Apache HTTP Server
Published on October 1, 2026
Apache HTTP Server: mod_auth_digest reauthentication attack
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Timeline
Report received
fixed in 2.4.x by r1937721 140 days later.
2.4.69 released
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-48005
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.0, <= 2.4.68 is affected.