Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-38709

26
FAUCET Score

CVE-2023-38709 is a high-severity vulnerability affecting Apache HTTP Server versions through 2.4.58, as well as products from Apple, Broadcom, Debian, Fedora Project, and NetApp. It stems from faulty input validation in Apache's core, allowing malicious backend/content generators to split HTTP responses. With a CVSS score of 7.3, this vulnerability is easily exploitable over the network with low complexity, potentially leading to partial loss of confidentiality, integrity, and availability. While there are no known public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV, Hot List), the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.59CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.91%
Probability of exploitation in next 30 days
EPSS Percentile
89.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0391 is in the 81st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

apachepatch availablevia llm_extracted
Fixed in: 2.4
microsoftpatch availablevia msrc
Product: 19781-17084Fixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: 17684-17084Fixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: 19953-17086Fixed in: 2.4.59-1
microsoftpatch availablevia msrc
Product: cbl2 httpd 2.4.59-1 on CBL Mariner 2.0Fixed in: 2.4.59-1
microsoftpatch availablevia msrc
Product: 17357-16823Fixed in: 2.4.59-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 2.4.59-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 2.4.59-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: azl3 httpd 2.4.58-4 on Azure Linux 3.0Fixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: azl3 httpd 2.4.61-1 on Azure Linux 3.0Fixed in: 2.4.61-1
microsoftpatch availablevia msrc
Product: cbl2 httpd 2.4.58-1 on CBL Mariner 2.0Fixed in: 2.4.59-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: httpd:2.4-8100020240612075645.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: httpd-0:2.4.62-1.el9
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: httpd
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-httpd-0:2.4.57-15.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.57-15.el7jbcs
View patch
ubuntupatch availablevia ubuntu_usn
Product: apache2 (bionic)Fixed in: 2.4.29-1ubuntu4.27+esm7
ubuntupatch availablevia ubuntu_usn
Product: apache2 (trusty)Fixed in: 2.4.7-1ubuntu4.22+esm12
ubuntupatch availablevia ubuntu_usn
Product: apache2 (xenial)Fixed in: 2.4.18-2ubuntu3.17+esm17
ubuntupatch availablevia ubuntu_usn
Product: apache2 (focal)Fixed in: 2.4.41-4ubuntu3.23+esm3
redhatend of lifevia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: httpd
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: httpd24-httpd
redhatend of lifevia redhat_api
Product: OpenShift PipelinesFixed in: httpd

Vendor Advisories (7)

ubuntuUSN-8338-1

Apache HTTP Server vulnerabilities

May 28, 2026
apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
microsoft2024-Nov/CVE-2023-38709

CVE-2023-38709

Nov 12, 2024
microsoft2024-Apr/CVE-2023-38709

Apache HTTP Server: HTTP response splitting

Apr 9, 2024
redhatCVE-2023-38709Moderate

httpd: HTTP response splitting

Apr 4, 2024
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

openwall.com / lists/oss-security/2025/07/10/2
openwall.com / lists/oss-security/2025/07/10/3
seclists.org / fulldisclosure/2024/Jul/18
Mailing ListThird Party Advisory
httpd.apache.org / security/vulnerabilities_24.html
Vendor Advisory
lists.debian.org / debian-lts-announce/2024/05/msg00013.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20240415-0013
Third Party Advisory
support.apple.com / kb/HT214119
Third Party Advisory
openwall.com / lists/oss-security/2024/04/04/3
Mailing ListThird Party Advisory