Sceawere
Vulnerability Detail
CVE-2026-73637UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mod_auth_digest Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-416 Use After Free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-10-01T17:17:31.000Z",
"pubdate": "2026-10-01T17:17:31.000Z",
"executiveSummary": "A critical use-after-free vulnerability exists in the mod_auth_digest module of the Apache HTTP Server, affecting all versions prior to 2.4.69. This flaw permits an unauthenticated remote attacker to induce memory corruption within the authentication state management process.\nThe vulnerability is triggered by concurrent Digest authentication requests under specific server configurations—specifically when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0. Successful exploitation leads to authentication state corruption, which poses significant security risks including potential bypass of authentication controls or service instability.\nThe impact is elevated due to the requirement of no prior authentication, allowing remote, unauthenticated threat actors to target the server. The flaw stems from improper memory lifecycle management during the handling of concurrent Digest authentication headers. Organizations utilizing Apache HTTP Server must prioritize upgrading to version 2.4.69 to remediate this vulnerability and restore the integrity of the authentication subsystem.",
"technicalDetails": "The vulnerability resides within the mod_auth_digest module, which is responsible for implementing RFC 2617 HTTP Digest Authentication. The root cause is a use-after-free condition occurring during the processing of Digest authentication headers when the server is configured with specific persistence settings, namely AuthDigestNcCheck (which mandates nonce count checking) or AuthDigestNonceLifetime set to 0 (which mandates immediate nonce expiration).\nIn the context of concurrent request processing, the module fails to maintain proper reference counting or synchronization when managing the memory associated with the authentication session state. When multiple requests arrive simultaneously that trigger the same digest verification logic, a race condition can occur. The vulnerability manifests when a request process frees a memory structure representing the authentication nonce or associated client session data while another concurrent thread is still actively referencing that same memory address.\nThe attack flow initiates when an unauthenticated remote attacker sends multiple, rapid, concurrent HTTP requests that include crafted Digest authentication headers. The server attempts to process these requests through the mod_auth_digest module. Because of the race condition, the asynchronous nature of thread-based request handling leads to a sequence where thread A deallocates the session object while thread B attempts to read or modify the same pointer.\nThis use-after-free creates a dangling pointer condition, which the attacker can potentially manipulate to corrupt the authentication state. By inducing this corruption, an attacker might interfere with the server’s ability to correctly track nonce counts or session states, potentially leading to a scenario where authentication mechanisms are bypassed or the server process crashes due to illegal memory access (denial of service).\nThe vulnerability is highly sensitive to the timing of concurrent requests and is strictly tied to the mod_auth_digest component. Because the flaw does not require the attacker to have valid credentials or prior access to the server, it is reachable directly from the network. The exploitation is facilitated by the server’s internal architecture for managing nonce state lifecycles. Users running affected versions (pre-2.4.69) are highly vulnerable to unauthorized state modification if these specific Digest authentication flags are active."
}