Vulnerability record · CVE-2020-35452 · published 10 June 2021
CVE-2020-35452: Apache HTTP Server mod_auth_digest stack overflow via crafted Digest nonce
Apache · Http Server
Apache HTTP Server versions 2.4.0 through 2.4.46 contain an out-of-bounds write in mod_auth_digest triggered by a specially crafted Digest nonce. The overflow is a single zero byte, and Apache states there is no report of it being exploitable and that the team could not create an exploit, though certain compilers or build options might make it possible with limited consequences.
Description
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Automated analysis
medium priorityThe CVSS score is high and EPSS is elevated, but the vendor reports no known exploit and describes the one-byte zero overflow as having limited consequences, so real-world risk is constrained.
What it is
Apache HTTP Server versions 2.4.0 through 2.4.46 contain an out-of-bounds write in mod_auth_digest triggered by a specially crafted Digest nonce. The overflow is a single zero byte, and Apache states there is no report of it being exploitable and that the team could not create an exploit, though certain compilers or build options might make it possible with limited consequences.
Impact
An unauthenticated remote attacker could send a crafted Digest nonce and cause a one-byte zero write past a stack buffer, potentially crashing the worker process or, under specific build conditions, corrupting adjacent stack data. The vendor describes any resulting impact as limited.
Attack surface
Reachable over the network through HTTP requests to a server that has mod_auth_digest enabled and is configured for Digest authentication. The CVSS vector shows no privileges or user interaction required, so the request can be sent directly to the service.
Exploitation
Not listed in CISA KEV and no ransomware group is documented using it. EPSS is high (0.53471, 98.9th percentile), but the vendor states no exploit has been reported or reproduced, so the score reflects theoretical rather than observed exploitation.
What to do
- Upgrade Apache HTTP Server to a version after 2.4.46 that contains the mod_auth_digest fix.
- If immediate upgrade is not possible, disable mod_auth_digest or switch affected virtual hosts from Digest to Basic authentication over TLS.
- Apply vendor patches from Debian, Fedora, Gentoo, NetApp, or Oracle for bundled or packaged httpd instances.
- Audit configurations for Digest authentication and remove it where it is not required.
- Monitor for repeated malformed Digest Authorization headers as a sign of attempted triggering.
Detection
- Search httpd error and access logs for malformed or unusually long Digest nonce values in Authorization headers.
- Alert on repeated worker process crashes or restarts on hosts running mod_auth_digest.
- Use network detection to flag HTTP requests with Digest Authorization headers that deviate from expected nonce format or length.
- Inventory Apache HTTP Server versions and flag any instance still in the 2.4.0 to 2.4.46 range.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-35452 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-35452), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.