CVE-2022-26377
published 2022-06-09CVE-2022-26377: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
19.01%
97.0th percentile
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.54 | 2.4.54 |
| apache_software_foundation | apache_http_server | Apache HTTP Server 2.4 – 2.4.53 | — |
| debian | apache2 | < apache2 2.4.54-1 (bookworm) | apache2 2.4.54-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
CISA ICS
Mitsubishi Electric MELSOFT iQ AppPortal
cisa_ics·2023-02-21·CVSS 7.5
[HIGH] Mitsubishi Electric MELSOFT iQ AppPortal
ICS Advisory
##
Mitsubishi Electric MELSOFT iQ AppPortal
Release DateFebruary 21, 2023
Alert CodeICSA-23-052-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric
- Equipment: MELSOFT iQ AppPortal
- Vulnerabilities: HTTP Request Smuggling, Insufficient Verification of Data Authenticity
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow a malicious attacker to make unidentified impacts such as authentication bypass, information disclosure, denial-of-service, or bypass IP address authentication.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Mitsubishi Electric products and versions are affected:
- MELSOFT iQ AppPortal (SW1DND-IQAPL-M):
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2022-06-23·CVSS 7.5
[HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-5487-1 introduced a regression in Apache HTTP Server.
USN-5487-1 fixed several vulnerabilities in Apache. Unfortunately, that update introduced
a regression when proxying balancer manager connections in some configurations
on Ubuntu 14.04 ESM. This update reverts those changes till further fix.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE-2022-26377)
It was discovered that Apache HTTP Server incorrectly handled certain
request. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-28614)
It wa
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2022-06-23·CVSS 7.5
CVE-2022-26377 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-5487-1 introduced a regression in Apache HTTP Server.
USN-5487-1 fixed several vulnerabilities in Apache HTTP Server.
Unfortunately it caused regressions. USN-5487-2 reverted the
patches that caused the regression in Ubuntu 14.04 ESM for further
investigation. This update re-adds the security fixes for Ubuntu
14.04 ESM and fixes two different regressions: one affecting mod_proxy
only in Ubuntu 14.04 ESM and another in mod_sed affecting also Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2022-06-21·CVSS 7.5
CVE-2022-29404 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE-2022-26377)
It was discovered that Apache HTTP Server incorrectly handled certain
request. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-28614)
It was discovered that Apache HTTP Server incorrectly handled certain request.
An attacker could possibly use this issue to cause a crash or expose
sensitive information. (CVE-2022-28615)
It was discovered that Apache HTTP Server incorrectly handled certain request.
An attacker could possibly use this issu
Red Hat
httpd: mod_proxy_ajp: Possible request smuggling
vendor_redhat·2022-06-08·CVSS 7.5
CVE-2022-26377 [HIGH] CWE-444 httpd: mod_proxy_ajp: Possible request smuggling
httpd: mod_proxy_ajp: Possible request smuggling
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd. This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests.
Statement: The httpd mod_proxy_ajp module is enabled by default on Red Hat Enterprise Linux 8, 9, and in RHSCL. However, there are no directives forwarding requests using the AJP protocol.
Mitigation: Disabling mod_proxy_ajp and restarting httpd will mitigate
Debian
CVE-2022-26377: apache2 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...
vendor_debian·2022·CVSS 7.5
CVE-2022-26377 [HIGH] CVE-2022-26377: apache2 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Scope: local
bookworm: resolved (fixed in 2.4.54-1)
bullseye: resolved (fixed in 2.4.54-1~deb11u1)
forky: resolved (fixed in 2.4.54-1)
sid: resolved (fixed in 2.4.54-1)
trixie: resolved (fixed in 2.4.54-1)
OSV
apache2 regression
osv·2022-06-23·CVSS 7.5
[HIGH] apache2 regression
apache2 regression
USN-5487-1 fixed several vulnerabilities in Apache. Unfortunately, that update introduced
a regression when proxying balancer manager connections in some configurations
on Ubuntu 14.04 ESM. This update reverts those changes till further fix.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE-2022-26377)
It was discovered that Apache HTTP Server incorrectly handled certain
request. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-28614)
It was discovered that Apache HTTP Server incorrectly handled certain request.
An attacker
OSV
apache2 regression
osv·2022-06-23·CVSS 7.5
[HIGH] apache2 regression
apache2 regression
USN-5487-1 fixed several vulnerabilities in Apache HTTP Server.
Unfortunately it caused regressions. USN-5487-2 reverted the
patches that caused the regression in Ubuntu 14.04 ESM for further
investigation. This update re-adds the security fixes for Ubuntu
14.04 ESM and fixes two different regressions: one affecting mod_proxy
only in Ubuntu 14.04 ESM and another in mod_sed affecting also Ubuntu 16.04 ESM
and Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE-2022-26377)
It was discovered that Apache HTTP Server incorrectly handled certain
re
OSV
apache2 vulnerabilities
osv·2022-06-21·CVSS 7.5
CVE-2022-26377 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that Apache HTTP Server mod_proxy_ajp incorrectly handled
certain crafted request. A remote attacker could possibly use this issue to
perform an HTTP Request Smuggling attack. (CVE-2022-26377)
It was discovered that Apache HTTP Server incorrectly handled certain
request. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-28614)
It was discovered that Apache HTTP Server incorrectly handled certain request.
An attacker could possibly use this issue to cause a crash or expose
sensitive information. (CVE-2022-28615)
It was discovered that Apache HTTP Server incorrectly handled certain request.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-29404)
It was discovered that Apache HTTP S
GHSA
GHSA-gx9q-f765-xrgg: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu
ghsa_unreviewed·2022-06-10
CVE-2022-26377 [HIGH] CWE-444 GHSA-gx9q-f765-xrgg: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
OSV
CVE-2022-26377: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu
osv·2022-06-09·CVSS 7.5
CVE-2022-26377 [HIGH] CVE-2022-26377: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
No detection rules found.
No public exploits indexed.
Tenable
CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
blogs_tenable·2023-10-27·CVSS 9.8
[CRITICAL] CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
HackerOne
Apache HTTP Server: mod_proxy_ajp: Possible request smuggling
hackerone·2022-07-09·CVSS 7.5
CVE-2022-26377 [HIGH] Apache HTTP Server: mod_proxy_ajp: Possible request smuggling
Apache HTTP Server: mod_proxy_ajp: Possible request smuggling
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
## Impact
Information disclosure, RCE
moderate: mod_proxy_ajp: Possible request smuggling (CVE-2022-26377)
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Acknowledgements: R
CTF
where_are_you_from / README
ctf_writeups·2022·CVSS 7.5
CVE-2022-26377 [HIGH] where_are_you_from / README
# Where are you from?
1. The web server is vulnerable to CVE-2022-26377, which means we can use Request Smuggling to send AJP Requests.
2. Following the writeup in [http://noahblog.360.cn/apache-httpd-ajp-request-smuggling/](http://noahblog.360.cn/apache-httpd-ajp-request-smuggling/), we are able to craft a AJP request that allows us to leak the source code (index.jsp).
```jsp
<%
String remote_addr = request.getRemoteAddr();
if (remote_addr.equals("119.29.29.29")){
String flag = System.getenv("flag");
out.println(flag);
}else {
out.print(remote_addr);
}
```
3. Then, we craft another request where we set the remote_addr to the fake address, and get the flag.
Exploit script: `gen.py` generates the payload which we can send to the server using the following command:
```
curl -vvv http:/
http://www.openwall.com/lists/oss-security/2022/06/08/2https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20220624-0005/http://www.openwall.com/lists/oss-security/2022/06/08/2https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20220624-0005/
2022-06-09
Published