CVE-2026-48005: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Affected products
- Apache HTTP Server: from 2.4.0, before 2.4.69 (fixed in 2.4.69)
Published 2026-10-01. Last modified 2026-10-06.