Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-5487-1 | Apache HTTP Server vulnerabilities |
Ubuntu USN |
USN-5487-3 | Apache HTTP Server regression |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T05:03:32.881Z
Reserved: 2022-03-03T00:00:00.000Z
Link: CVE-2022-26377
No data.
Status : Analyzed
Published: 2022-06-09T17:15:09.077
Modified: 2025-05-01T15:35:56.423
Link: CVE-2022-26377
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN