apache http-server CVE-2026-73637 is a vulnerability in Apache HTTP Server
Published on October 1, 2026

Apache HTTP Server: mod_auth_digest DoS attack
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Vendor Advisory NVD

Timeline

Report received

fixed in 2.4.x by r1937721 75 days later.

2.4.69 released

Weakness Type

What is a Dangling pointer Vulnerability?

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

CVE-2026-73637 has been classified to as a Dangling pointer vulnerability or weakness.


Products Associated with CVE-2026-73637

Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache HTTP Server: