Bug 2544814 (CVE-2026-73637)

Summary: CVE-2026-73637 httpd: httpd: Authentication state corruption via concurrent Digest authentication requests
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: csutherl, jclere, pjindal, plodge, rhel-process-autobot, szappis, vchlup, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in httpd's mod_auth_digest module. A use-after-free vulnerability allows an unauthenticated remote attacker to corrupt the server's authentication state by submitting concurrent Digest authentication requests. This issue occurs when specific configuration settings, such as nonce checking (AuthDigestNcCheck) or zero-duration nonce lifetimes (AuthDigestNonceLifetime), are enabled.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2545095    
Bug Blocks:    

Description OSIDB Bzimport 2026-10-01 23:03:07 UTC
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.

Users are recommended to upgrade to version 2.4.69, which fixes this issue.