CVE-2022-36760 is a critical HTTP Request Smuggling vulnerability in Apache HTTP Server's mod_proxy_ajp, affecting versions 2.4.54 and prior. With a CVSS score of 9.0, this flaw allows remote attackers to smuggle requests to the AJP backend, potentially leading to high impact on confidentiality, integrity, and availability with high complexity. While no public exploits or Metasploit modules are available, and it's not in the KEV catalog, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4, <= 2.4.54CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.55CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_proxy_ajp: Possible request smuggling
Jan 17, 2023Apache HTTP Server: mod_proxy_ajp Possible request smuggling
Jan 10, 2023Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project