CVE-2022-37436
published 2023-01-17CVE-2022-37436: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into…
PriorityP343medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
57.94%
99.0th percentile
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.55 | 2.4.55 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | < 2.4.55 | 2.4.55 |
| debian | apache2 | < apache2 2.4.55-1 (bookworm) | apache2 2.4.55-1 (bookworm) |
| msrc | azl3_mod_http2_2.0.29-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.55-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_httpd_2.4.55-1_on_cbl_mariner_1.0 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is in Apache HTTP Server mod_proxy module — monitor for HTTP responses where security-relevant headers (e.g., Content-Security-Policy, X-Frame-Options, Set-Cookie) are absent or appear in the response body rather than headers, which may indicate a malicious backend is exploiting header truncation. ↗
- →The flaw is triggered via malformed/bad headers from a backend — inspect mod_proxy error logs for header parsing errors that coincide with truncated response headers being passed to clients. ↗
- →This flaw is only exploitable via a malicious or compromised backend/application — focus detection on backend-to-proxy traffic anomalies and unexpected header content appearing in response bodies proxied through mod_proxy. ↗
- ·Only Apache HTTP Server versions prior to 2.4.55 are vulnerable; the fix was released in 2.4.55 on 2023-01-17. Red Hat Enterprise Linux 6 is explicitly not affected. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_apache5.3
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache2 vulnerability
osv·2023-02-02·CVSS 5.3
CVE-2022-37436 [MEDIUM] apache2 vulnerability
apache2 vulnerability
USN-5839-1 fixed a vulnerability in Apache. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy module incorrectly truncated certain response headers. This may
result in later headers not being interpreted by the client.
(CVE-2022-37436)
OSV
apache2 vulnerabilities
osv·2023-02-01·CVSS 7.5
CVE-2006-20001 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
It was discovered that the Apache HTTP Server mod_dav module incorrectly
handled certain If: request headers. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
(CVE-2006-20001)
ZeddYu_Lu discovered that the Apache HTTP Server mod_proxy_ajp module
incorrectly interpreted certain HTTP Requests. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-36760)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy module incorrectly truncated certain response headers. This may
result in later headers not being interpreted by the client.
(CVE-2022-37436)
GHSA
GHSA-3f78-wq4j-7vgr: Prior to Apache HTTP Server 2
ghsa_unreviewed·2023-01-17
CVE-2022-37436 [MEDIUM] CWE-113 GHSA-3f78-wq4j-7vgr: Prior to Apache HTTP Server 2
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
OSV
CVE-2022-37436: Prior to Apache HTTP Server 2
osv·2023-01-17·CVSS 5.3
CVE-2022-37436 [MEDIUM] CVE-2022-37436: Prior to Apache HTTP Server 2
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2022-37436
vendor_oracle·2023-10-15·CVSS 5.3
CVE-2022-37436 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2022-37436
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) vulnerability
CVE: CVE-2022-37436
CVSS: 5.3
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Ubuntu
Apache HTTP Server vulnerability
vendor_ubuntu·2023-02-02·CVSS 5.3
CVE-2022-37436 [MEDIUM] Apache HTTP Server vulnerability
Title: Apache HTTP Server vulnerability
Summary: Several security issues were fixed in Apache HTTP Server.
USN-5839-1 fixed a vulnerability in Apache. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy module incorrectly truncated certain response headers. This may
result in later headers not being interpreted by the client.
(CVE-2022-37436)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2023-02-01·CVSS 7.5
CVE-2006-20001 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that the Apache HTTP Server mod_dav module incorrectly
handled certain If: request headers. A remote attacker could possibly use
this issue to cause the server to crash, resulting in a denial of service.
(CVE-2006-20001)
ZeddYu_Lu discovered that the Apache HTTP Server mod_proxy_ajp module
incorrectly interpreted certain HTTP Requests. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-36760)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy module incorrectly truncated certain response headers. This may
result in later headers not being interpreted by the client.
(CVE-2022-37436)
Red Hat
httpd: mod_proxy: HTTP response splitting
vendor_redhat·2023-01-17·CVSS 5.3
CVE-2022-37436 [MEDIUM] CWE-113 httpd: mod_proxy: HTTP response splitting
httpd: mod_proxy: HTTP response splitting
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
A flaw was found in the mod_proxy module of httpd. A malicious backend can cause the response headers to be truncated because they are not cleaned when an error is found while reading them, resulting in some headers being incorporated into the response body and not being interpreted by a client.
Statement: This flaw is only exploitable via bad headers generated by a malicious backend or a malicious application.
httpd as shipped in Red Hat Enterprise Linux 7, 8, 9 and in RHSCL is
Microsoft
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
vendor_msrc·2023-01-10·CVSS 5.3
CVE-2022-37436 [MEDIUM] CWE-113 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CB
Debian
CVE-2022-37436: apache2 - Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response h...
vendor_debian·2022·CVSS 5.3
CVE-2022-37436 [MEDIUM] CVE-2022-37436: apache2 - Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response h...
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
Scope: local
bookworm: resolved (fixed in 2.4.55-1)
bullseye: resolved (fixed in 2.4.56-1~deb11u1)
forky: resolved (fixed in 2.4.55-1)
sid: resolved (fixed in 2.4.55-1)
trixie: resolved (fixed in 2.4.55-1)
Apache
Apache httpd: CVE-2022-37436
vendor_apache·CVSS 5.3
CVE-2022-37436 Apache httpd: CVE-2022-37436
Apache httpd: CVE-2022-37436
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client. Acknowledgements: finder: Dimas Fariski Setyawan Putra (@nyxsorcerer) Reported to security team 2022-07-14 Update 2.4.55 released 2023-01-17 Affects before 2.4.55
Severity: moderate
Affected versions: 2.4.55
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-17
Published