Описание
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apache HTTP Server: from through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
A flaw was found in httpd. When processing responses from an untrusted or compromised backend server, multiple modules fail to sanitize Carriage Return and Line Feed (CRLF) sequences in the HTTP status line. This issue leads to an HTTP response splitting attack.
Отчет
To exploit this vulnerability, the Apache HTTP Server must be configured to connect to an untrusted or compromised backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity.
Меры по смягчению последствий
To mitigate this issue, ensure that Apache HTTP Server (httpd) is configured to proxy only to trusted backend services. Implement robust network segmentation and access controls to restrict unauthorized access to backend servers. If proxying to potentially untrusted backends is necessary, consider deploying a Web Application Firewall (WAF) or an additional content inspection layer to filter malicious response headers.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 7 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | httpd | Out of support scope | ||
| Red Hat Hardened Images | httpd-main-2.4.67-1.hum1 | Fixed | RHSA-2026:17080 | 13.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
HTTP response splitting vulnerability in multiple Apache HTTP Server m ...
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
EPSS
6.5 Medium
CVSS3