CVE-2016-8743 describes a vulnerability in Apache HTTP Server versions prior to 2.2.32 and 2.4.25, where its lax handling of whitespace in HTTP requests and responses could lead to request smuggling, response splitting, and cache pollution when acting as a proxy or interacting with backend servers. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in high integrity impact. While the EPSS and FAUCET scores suggest some potential, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage directly related to this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, <= 2.2.31CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.1, <= 2.4.23CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: Apache HTTP Request Parsing Whitespace Defects
Dec 20, 2016Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project