Description
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Remediation
References
Related Vulnerabilities
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2026-42767)
Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2021-41824)
Zope Web Application Server Cryptographic Issues Vulnerability (CVE-2012-6661)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2016-8627)
Apache HTTP Server CVE-2013-1896 Vulnerability (CVE-2013-1896)