Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2005-2088

24
FAUCET Score

CVE-2005-2088 describes an HTTP Request Smuggling vulnerability affecting Apache HTTP Server versions prior to 1.3.34 and 2.0.55 when configured as an HTTP proxy. This flaw allows remote attackers to poison web caches, bypass web application firewalls, and conduct Cross-Site Scripting (XSS) attacks. The vulnerability arises from Apache's incorrect handling of HTTP requests containing both "Transfer-Encoding: chunked" and "Content-Length" headers, leading to the receiving server processing the request body as a separate HTTP request. Rated with a CVSS score of 4.3 (Medium), this vulnerability has a network attack vector and medium attack complexity, with a potential impact on integrity (partial). Its high EPSS score (0.46689) and FAUCET Risk Score of 96/100 suggest a significant likelihood of exploitation despite its age. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of older vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.35, < 2.0.55CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:*
3.1CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
20.46%
Probability of exploitation in next 30 days
EPSS Percentile
97.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.2046 is in the 98th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-46.2.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd-0:2.0.52-12.1.ent
View patch

Vendor Advisories (1)

redhatCVE-2005-2088Moderate

security flaw

Jun 12, 2005

References

docs.info.apple.com / article.html
Broken Link
lists.trustix.org / pipermail/tsl-announce/2005-October/000354.html
Broken Link
marc.info
Mailing ListThird Party Advisory
seclists.org / lists/bugtraq/2005/Jun/0025.html
Issue TrackingMailing ListThird Party Advisory
secunia.com / advisories/14530
Not Applicable
secunia.com / advisories/17319
Not Applicable
secunia.com / advisories/17487
Not Applicable
secunia.com / advisories/17813
Not Applicable
secunia.com / advisories/19072
Not Applicable
secunia.com / advisories/19073
Not Applicable
secunia.com / advisories/19185
Not Applicable
secunia.com / advisories/19317
Not Applicable
secunia.com / advisories/23074
Not Applicable
securityreason.com / securityalert/604
ExploitThird Party Advisory
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
slackware.com / security/viewer.php
Third Party Advisory
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r734a07156abf332d5ab27fb91d9d962cacfef4f3681e44056f064fa8%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/re895fc1736d25c8cf57e102c871613b8aeec9ea26fd8a44e7942b5ab%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Mailing ListVendor Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11452
Broken LinkThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1237
Broken LinkThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1526
Broken LinkThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1629
Broken LinkThird Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A840
Broken LinkThird Party Advisory
secure-support.novell.com / KanisaPlatform/Publishing/741/3222109_f.SAL_Public.html
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.avaya.com / elmodocs2/security/ASA-2006-081.htm
Third Party Advisory
www-1.ibm.com / support/search.wss
Broken LinkThird Party Advisory
www-1.ibm.com / support/search.wss
Broken LinkThird Party Advisory
www1.itrc.hp.com / service/cki/docDisplay.do
Broken Link
apache.org / dist/httpd/CHANGES_1.3
Broken LinkVendor Advisory
apache.org / dist/httpd/CHANGES_2.0
Broken LinkVendor Advisory
debian.org / security/2005/dsa-803
Mailing ListThird Party Advisory
debian.org / security/2005/dsa-805
Mailing ListThird Party Advisory
mandriva.com / security/advisories
Third Party Advisory
novell.com / linux/security/advisories/2005_18_sr.html
Broken Link
novell.com / linux/security/advisories/2005_46_apache.html
Broken Link
redhat.com / support/errata/RHSA-2005-582.html
Broken LinkThird Party Advisory
securiteam.com / securityreviews/5GP0220G0U.html
Broken LinkExploit
securityfocus.com / archive/1/428138/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/14106
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/15647
Broken LinkThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-160-2
Broken Link
vupen.com / english/advisories/2005/2140
Broken LinkPermissions Required
vupen.com / english/advisories/2005/2659
Broken LinkPermissions Required
vupen.com / english/advisories/2006/0789
Broken LinkPermissions Required
vupen.com / english/advisories/2006/1018
Broken LinkPermissions Required
vupen.com / english/advisories/2006/4680
Broken LinkPermissions Required
watchfire.com / resources/HTTP-Request-Smuggling.pdf
Broken Link