Fedora Account System
Red Hat Associate
Red Hat Customer
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:41906 https://access.redhat.com/errata/RHSA-2026:41906