apache http-server CVE-2026-48005 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_auth_digest reauthentication attack
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Vendor Advisory NVD

Timeline

Report received

fixed in 2.4.x by r1937721 140 days later.

2.4.69 released

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-48005

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: