cbcvebase.
CVE-2022-37436
published 2023-01-17

CVE-2022-37436: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into…

PriorityP343medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
57.94%
99.0th percentile
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

Affected

11 ranges
VendorProductVersion rangeFixed in
apachehttp_server< 2.4.552.4.55
apachehttpd
apache_software_foundationapache_http_server< 2.4.552.4.55
debianapache2< apache2 2.4.55-1 (bookworm)apache2 2.4.55-1 (bookworm)
msrcazl3_mod_http2_2.0.29-3_on_azure_linux_3.0
msrccbl2_httpd_2.4.55-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_httpd_2.4.55-1_on_cbl_mariner_1.0

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in Apache HTTP Server mod_proxy module — monitor for HTTP responses where security-relevant headers (e.g., Content-Security-Policy, X-Frame-Options, Set-Cookie) are absent or appear in the response body rather than headers, which may indicate a malicious backend is exploiting header truncation.
  • The flaw is triggered via malformed/bad headers from a backend — inspect mod_proxy error logs for header parsing errors that coincide with truncated response headers being passed to clients.
  • This flaw is only exploitable via a malicious or compromised backend/application — focus detection on backend-to-proxy traffic anomalies and unexpected header content appearing in response bodies proxied through mod_proxy.
  • ·Only Apache HTTP Server versions prior to 2.4.55 are vulnerable; the fix was released in 2.4.55 on 2023-01-17. Red Hat Enterprise Linux 6 is explicitly not affected.

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_apache5.3
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.