CVE-2026-73636
Description
A flaw was found in the mod_auth_digest module of the Apache HTTP Server. This vulnerability allows an attacker positioned on the network to bypass authentication by replaying previously intercepted user credentials. When the server is configured with a nonce (a single-use security token) lifetime of zero, an attacker can send crafted requests that prematurely clear the client session entry from shared memory, enabling unauthorized access using the replayed credentials.
Mitigation
Ensure that `AuthDigestNonceLifetime` is not set to `0`. If digest authentication is not required, disable `mod_auth_digest`.
1. To retain digest authentication with safe settings, set a positive non-zero value (such as the default 300 seconds) or remove the explicit zero setting from `/etc/httpd/conf/httpd.conf` or relevant files in `/etc/httpd/conf.d/`:
AuthDigestNonceLifetime 300
2. If HTTP digest authentication is not needed, disable the module by commenting out the corresponding line in `/etc/httpd/conf.modules.d/00-base.conf`:
#LoadModule auth_digest_module modules/mod_auth_digest.so
3. Restart the web server to apply changes:
systemctl restart httpd
Warning: Restarting or reloading the httpd service will briefly disrupt active client connections. Disabling the module will break authentication for virtual hosts or directories relying on digest authentication.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 8.1 | N/A | 8.1 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | High | N/A | High |
| Integrity Impact | High | N/A | High |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
Messages sent with a capture-relay attack allow access to resources which are not otherwise accessible without proper authentication.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.