Overview
What is CVE-2026-33006?
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Vulnerability intelligence
CVE-2026-33006 and is rated Medium severity with a CVSS score of 4.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.