CVE-2026-73637 is a vulnerability in Apache HTTP Server
Published on October 1, 2026
Apache HTTP Server: mod_auth_digest DoS attack
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.
Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Timeline
Report received
fixed in 2.4.x by r1937721 75 days later.
2.4.69 released
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2026-73637 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2026-73637
Want to know whenever a new CVE is published for Apache HTTP Server? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache HTTP Server:- Version 2.4.0, <= 2.4.68 is affected.