CVE-2022-37436 is a medium-severity vulnerability affecting Apache HTTP Server versions prior to 2.4.55. A malicious backend can truncate response headers, causing security-relevant headers to be misinterpreted by clients. This issue has a CVSS score of 5.3, indicating a network-based attack with low complexity, resulting in a potential loss of integrity. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion is minimal, with only two mentions, primarily concerning IBM HTTP Server.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2.4.55CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
< 2.4.55CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025CVE-2022-37436
Feb 14, 2023httpd: mod_proxy: HTTP response splitting
Jan 17, 2023Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
Jan 10, 2023Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project