Use After Free Vulnerability in Apache HTTP Server by Apache Software Foundation
CVE-2026-73637

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-73637?

A use after free vulnerability exists in the mod_auth_digest module of Apache HTTP Server versions prior to 2.4.69. This flaw allows unauthenticated remote clients to trigger authentication state corruption by sending concurrent Digest authentication requests, especially when the AuthDigestNcCheck directive is enabled or the AuthDigestNonceLifetime is set to zero. Administrators are advised to update their Apache HTTP Server installations to version 2.4.69 or later to mitigate this security issue.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhen Kong
Darren Carreras (DarrenC)
.