Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33523

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

A flaw was found in httpd. When processing responses from an untrusted or compromised backend server, multiple modules fail to sanitize Carriage Return and Line Feed (CRLF) sequences in the HTTP status line. This issue leads to an HTTP response splitting attack.

Отчет

To exploit this vulnerability, the Apache HTTP Server must be configured to connect to an untrusted or compromised backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this issue, ensure that Apache HTTP Server (httpd) is configured to proxy only to trusted backend services. Implement robust network segmentation and access controls to restrict unauthorized access to backend servers. If proxying to potentially untrusted backends is necessary, consider deploying a Web Application Firewall (WAF) or an additional content inspection layer to filter malicious response headers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdFix deferred
Red Hat Enterprise Linux 6httpdFix deferred
Red Hat Enterprise Linux 7httpdFix deferred
Red Hat Enterprise Linux 8httpd:2.4/httpdFix deferred
Red Hat Enterprise Linux 9httpdOut of support scope
Red Hat Hardened Imageshttpd-main-2.4.67-1.hum1FixedRHSA-2026:1708013.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2465297httpd: HTTP response splitting forwarding malicious status line

EPSS

Процентиль: 36%
0.00436
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 6.5
nvd
3 месяца назад

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

CVSS3: 6.5
msrc
3 месяца назад

Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line

CVSS3: 6.5
debian
3 месяца назад

HTTP response splitting vulnerability in multiple Apache HTTP Server m ...

CVSS3: 6.5
github
3 месяца назад

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

EPSS

Процентиль: 36%
0.00436
Низкий

6.5 Medium

CVSS3