CVE-2026-33006
Security update for apache2
Description
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Metrics
Weakness classes (CWE)
CWE-208Base
Observable Timing Discrepancy
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
apache
http_server2.4.67
bitnami
apache2.4.0
bitnami
apache2.4.30
bitnami
apache2.4.66
bitnami
apache
References & sources
- https://httpd.apache.org/security/vulnerabilities_24.htmleuvd
- http://www.openwall.com/lists/oss-security/2026/05/05/6
- https://nvd.nist.gov/vuln/detail/CVE-2026-29168web
- http://www.openwall.com/lists/oss-security/2026/05/04/20
- http://www.openwall.com/lists/oss-security/2026/05/05/12
- https://nvd.nist.gov/vuln/detail/CVE-2026-29169web
- http://www.openwall.com/lists/oss-security/2026/05/04/18
- https://nvd.nist.gov/vuln/detail/CVE-2026-24072web
- http://www.openwall.com/lists/oss-security/2026/05/05/9web
- https://nvd.nist.gov/vuln/detail/CVE-2026-28780web
- https://access.redhat.com/errata/RHSA-2026:21391web
- https://access.redhat.com/errata/RHSA-2026:21433web
- https://access.redhat.com/errata/RHSA-2026:22140web
- https://access.redhat.com/errata/RHSA-2026:27200web
- https://access.redhat.com/errata/RHSA-2026:27201web
- https://access.redhat.com/security/cve/CVE-2026-28780web
- https://bugzilla.redhat.com/show_bug.cgi?id=2466913web
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.jsonweb
- https://access.redhat.com/errata/RHSA-2026:36373web
- https://access.redhat.com/errata/RHSA-2026:36831web
Linked CVEs
- CVE-2026-34059
Buffer Over-read vulnerability in Apache HTTP Server.
highCVSSv3 7.5 - CVE-2026-34032
Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server.
mediumCVSSv3 5.3 - CVE-2026-33857
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server.
mediumCVSSv3 5.3 - CVE-2026-33523
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
mediumCVSSv3 6.5 - CVE-2026-33007
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to cra…
mediumCVSSv3 5.3 - CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a mali…
highCVSSv3 7.5 - CVE-2026-29168
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
highCVSSv3 7.3 - CVE-2026-28780
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
criticalCVSSv3 9.8 - CVE-2026-24072
A flaw was found in Apache HTTP Server.
highCVSSv3 8.8 - CVE-2026-23918
Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol.
highCVSSv3 8.8