CVE-2023-38709 is a high-severity vulnerability affecting Apache HTTP Server versions through 2.4.58, as well as products from Apple, Broadcom, Debian, Fedora Project, and NetApp. It stems from faulty input validation in Apache's core, allowing malicious backend/content generators to split HTTP responses. With a CVSS score of 7.3, this vulnerability is easily exploitable over the network with low complexity, potentially leading to partial loss of confidentiality, integrity, and availability. While there are no known public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV, Hot List), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.59CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server vulnerabilities
May 28, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025CVE-2023-38709
Nov 12, 2024Apache HTTP Server: HTTP response splitting
Apr 9, 2024httpd: HTTP response splitting
Apr 4, 2024Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project