{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-48005: Apache HTTP Server: mod_auth_digest reauthentication attack",
  "message-id": "<05174974-afdd-5921-5f68-326021d30378@apache.org>",
  "mid": "hx0rr3krc95q494ccjb2588jrp1xmqtp",
  "permalinks": [
    "hx0rr3krc95q494ccjb2588jrp1xmqtp",
    "rb298aa1d71e48d818c6aadd7ffe39f94abd2c6e4c45547bd63e05215@<dev.httpd.apache.org>"
  ],
  "dbid": "3fa12aa43ab4448d93601d2a7f39555d6b0021b58c0746932c9216d91f066cbb",
  "cc": "",
  "epoch": 1790877863,
  "list": "<dev.httpd.apache.org>",
  "list_raw": "<dev.httpd.apache.org>",
  "date": "2026/10/01 18:04:23",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nMissing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck .\n\nUsers are recommended to upgrade to version 2.4.69, which fixes this issue.\n\nCredit:\n\nlokerxx (finder)\nZhen Kong (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-48005\n\nTimeline:\n\n2026-05-14: Report received\n2026-10-01: fixed in 2.4.x by r1937721\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.0 through 2.4.68\n\nDescription:\n\nMissing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@httpd.apache.org",
  "size": 3949,
  "id": "hx0rr3krc95q494ccjb2588jrp1xmqtp"
}