CVE-2026-73636 concerns a flaw in mod_auth_digest, the Digest authentication module in Apache HTTP Server. The stated severity is low, and affected versions range from 2.4.0 through 2.4.68 on all platforms.
The report says a man-in-the-middle (MITM) attacker may replay captured Digest credentials under specific conditions. Crafted requests can trigger garbage collection of a client shared-memory entry. The supplied excerpt ends mid-sentence while describing AuthDigestNonceLifetime, so it does not establish the complete condition or which configuration is required for exploitation.
Apache administrators should inventory deployed versions and compare their installations with the project's official security notices. Do not infer from this excerpt alone that a particular version fixes the flaw; confirm the guidance and fixed version in official sources before planning an upgrade.
To consult and verify the report, search for CVE-2026-73636 in the oss-sec feed and Apache notices, checking the date, affected range, and full conditions. If using AI to summarize the notice or prepare a change, share only public excerpts or de-identified technical data, not credentials, secret configuration, or internal organizational information.