HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, <= 2.4.66CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.67CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server vulnerabilities
Jul 20, 2026Apache HTTP Server vulnerabilities
May 6, 2026CVE-2026-33523: Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
May 4, 2026Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
May 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025