CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-73636

CVE-2026-73636. CVSS base score 8.1 (HIGH, Source advisory). EPSS 0.00368 (percentile 0.28328), scored 2026-10-04.

Affected technology

http server · from 2.4.0 (inclusive), before 2.4.69 (exclusive)
apache

Apache HTTP Server · 2.4.0 through 2.4.68
Apache Software Foundation

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

A man-in-the-middle (MITM) attacker can replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Source advisory’s CVSS 3.1 assessment rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-294
CCR priority
32.5 /100 (P4)
CVSS
8.1 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · Source advisory
EPSS
0.00368 · percentile 0.28328 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-73636.html