Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-3183

53
FAUCET Score

CVE-2015-3183 is a vulnerability in the chunked transfer coding implementation of Apache HTTP Server versions prior to 2.4.14. It allows remote attackers to perform HTTP request smuggling attacks by crafting requests with large chunk-size values or invalid chunk-extension characters. The vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity, requiring no authentication, and potentially leading to partial integrity impact. While the EPSS and FAUCET scores suggest a moderate risk, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion beyond a single mention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.2.0, < 2.2.31CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 2.4.0, < 2.4.16CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
73.33%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.7333 is in the 100th percentile among its peer group of 23,690 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (51)

apachepatch availablevia llm_extracted
Fixed in: 2.4
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: httpd-0:2.4.6-31.ael7b_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: hornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: httpd-0:2.2.26-54.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: jbcs-httpd24-0:1-3.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: mod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: mod_jk-0:1.2.41-2.redhat_4.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6Fixed in: tomcat-native-0:1.1.34-5.redhat_1.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: hornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: httpd22-0:2.2.26-56.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: jbcs-httpd24-0:1-3.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: mod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: mod_jk-0:1.2.41-2.redhat_4.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7Fixed in: tomcat-native-0:1.1.34-5.redhat_1.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 5Fixed in: httpd-0:2.2.26-41.ep6.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 5Fixed in: mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 6Fixed in: httpd-0:2.2.26-41.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 6Fixed in: mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 7Fixed in: httpd22-0:2.2.26-42.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2 for RHEL 7Fixed in: mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 2.1Fixed in: httpd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: apache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: httpd24-0:2.4.6-59.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: mod_bmx-0:0.9.5-7.GA.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: mod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat7-0:7.0.59-42_patch_01.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat8-0:8.0.18-52_patch_01.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: apache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: httpd24-0:2.4.6-59.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: mod_bmx-0:0.9.5-7.GA.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: mod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat8-0:8.0.18-52_patch_01.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSFixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSFixed in: httpd24-httpd-0:2.4.12-4.el6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-httpd-0:2.4.12-6.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSFixed in: httpd24-httpd-0:2.4.12-6.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat7-0:7.0.59-42_patch_01.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: httpd-0:2.2.15-47.el6_7
View patch
redhatno patchvia redhat_api
Product: CloudForms Management Engine 5Fixed in: httpd
redhatend of lifevia redhat_api
Product: Red Hat Directory Server 8Fixed in: httpd
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: httpd
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 1Fixed in: httpd

Vendor Advisories (4)

apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
redhatCVE-2015-3183Moderate

httpd: HTTP request smuggling attack against chunked request parser

Jul 15, 2015
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

httpd.apache.org / security/vulnerabilities_24.html
Vendor Advisory
kb.juniper.net / InfoCenter/index
Third Party Advisory
lists.apple.com / archives/security-announce/2015/Aug/msg00001.html
Mailing List
lists.apple.com / archives/security-announce/2015/Sep/msg00004.html
Mailing List
lists.opensuse.org / opensuse-updates/2015-10/msg00011.html
Third Party Advisory
marc.info
Mailing ListThird Party AdvisoryVDB Entry
rhn.redhat.com / errata/RHSA-2015-1666.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1667.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1668.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-2661.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-0061.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-0062.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2054.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2055.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-2056.html
Third Party Advisory
access.redhat.com / errata/RHSA-2015:2659
Third Party Advisory
access.redhat.com / errata/RHSA-2015:2660
Third Party Advisory
github.com / apache/httpd/commit/a6027e56924bb6227c1fdbf6f91e7e2438338be6
Third Party Advisory
github.com / apache/httpd/commit/e427c41257957b57036d5a549b260b6185d1dd73
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20564.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party AdvisoryVDB Entry
lists.apache.org / thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
puppet.com / security/cve/CVE-2015-3183
Third Party Advisory
security.gentoo.org / glsa/201610-02
Third Party Advisory
support.apple.com / HT205219
Third Party AdvisoryVDB Entry
support.apple.com / kb/HT205031
Third Party AdvisoryVDB Entry
apache.org / dist/httpd/CHANGES_2.4
Vendor Advisory
debian.org / security/2015/dsa-3325
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
Patch
oracle.com / technetwork/topics/security/bulletinoct2015-2511968.html
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/cpujan2016-2367955.html
PatchThird Party Advisory
oracle.com / technetwork/topics/security/cpuoct2015-2367953.html
Third Party AdvisoryVDB Entry
securityfocus.com / bid/75963
Third Party AdvisoryVDB Entry
securityfocus.com / bid/91787
Third Party AdvisoryVDB Entry
securitytracker.com / id/1032967
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2686-1
Third Party Advisory