Back

HIGH

Apache HTTP Server: mod_auth_digest reauthentication attack

Published Oct 1, 2026

Description

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .

Users are recommended to upgrade to version 2.4.69, which fixes this issue.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, disable nonce-count verification by setting `AuthDigestNcCheck Off` within the relevant configuration context in `/etc/httpd/conf/httpd.conf` or `/etc/httpd/conf.d/`: AuthDigestNcCheck Off Alternatively, if Digest authentication is not required, disable `mod_auth_digest` by commenting out the corresponding `LoadModule auth_digest_module` line in `/etc/httpd/conf.modules.d/00-base.conf`. After modifying the configuration, reload the service: systemctl reload httpd Caveats: Disabling `AuthDigestNcCheck` removes server-side nonce-count checking, reducing replay protection for Digest authentication. Warning: Reloading the httpd service can momentarily disrupt in-flight connections.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Undergoing Analysis
Modified Oct 2, 2026
Red Hat
Severity Low
Public date Oct 1, 2026