CVE-2023-27522 is an HTTP Response Smuggling vulnerability affecting Apache HTTP Server versions 2.4.30 through 2.4.55 when using mod_proxy_uwsgi. This flaw allows special characters in origin response headers to truncate or split responses forwarded to clients. Rated 7.5 HIGH, it has a network attack vector, low attack complexity, and can lead to high integrity impact without requiring user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.30, < 2.4.56CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
< 2.0.22CPE matchmatch criteria | cpe:2.3:a:unbit:uwsgi:*:*:*:*:*:*:*:* | ||
>= 2.4.30, <= 2.4.55CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
Mar 14, 2023Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
Mar 7, 2023httpd: mod_proxy_uwsgi HTTP response splitting
Mar 7, 2023Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project