AZL-106758

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106758.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106758
Upstream
  • CVE-2026-73636
Published
2026-10-01T17:17:30Z
Modified
2026-10-11T05:36:19Z
Summary
CVE-2026-73636 affecting package httpd 2.4.68-1
Details

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0.

Users are recommended to upgrade to version 2.4.69, which fixes this issue.

References

Affected packages

Azure Linux:3 / httpd

Package

Name
httpd
Purl
pkg:rpm/azure-linux/httpd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.4.68-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106758.json"