CVE-2023-27522
published 2023-03-07CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.13%
79.9th percentile
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origin response header can truncate/split the response forwarded to the client.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.30 < 2.4.56 | 2.4.56 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.30 – 2.4.55 | — |
| debian | apache2 | < apache2 2.4.56-1 (bookworm) | apache2 2.4.56-1 (bookworm) |
| debian | debian_linux | — | — |
| msrc | cbl2_httpd_2.4.56-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.56-1_on_cbl_mariner_1.0 | — | — |
| unbit | uwsgi | < 2.0.22 | 2.0.22 |
| unbit | uwsgi | >= 0 < 2.0.22 | 2.0.22 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_apache7.5
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
apache2 vulnerabilities
osv·2023-03-09·CVSS 9.8
CVE-2023-25690 [CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy_uwsgi module incorrectly handled certain special characters. A
remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-27522)
GHSA
Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
ghsa·2023-03-07
CVE-2023-27522 [HIGH] CWE-444 Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.
OSV
CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi
osv·2023-03-07·CVSS 7.5
CVE-2023-27522 [HIGH] CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
OSV
Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
osv·2023-03-07
CVE-2023-27522 [HIGH] Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server from 2.4.30 through 2.4.55 and the uWSGI PyPI package prior to version 2.0.22. Special characters in the origin response header can truncate/split the response forwarded to the client.
OSV
CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi
osv·2023-03-07·CVSS 7.5
CVE-2023-27522 [HIGH] CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origin response header can truncate/split the response forwarded to the client.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Microsoft
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
vendor_msrc·2023-03-14·CVSS 7.5
CVE-2023-27522 [HIGH] CWE-444 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2023-03-09·CVSS 9.8
CVE-2023-27522 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy_uwsgi module incorrectly handled certain special characters. A
remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-27522)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
httpd: mod_proxy_uwsgi HTTP response splitting
vendor_redhat·2023-03-07·CVSS 7.5
CVE-2023-27522 [HIGH] CWE-113 httpd: mod_proxy_uwsgi HTTP response splitting
httpd: mod_proxy_uwsgi HTTP response splitting
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in the origin response header can truncate/split the response forwarded to the client.
An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.
Statement: The HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi has been categorized as moderate severity for Red Hat Enterprise Linux due to several technical factors. While the potential impact of this vulnerability is signi
Debian
CVE-2023-27522: apache2 - HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi....
vendor_debian·2023·CVSS 7.5
CVE-2023-27522 [HIGH] CVE-2023-27522: apache2 - HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi....
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
Scope: local
bookworm: resolved (fixed in 2.4.56-1)
bullseye: resolved (fixed in 2.4.56-1~deb11u1)
forky: resolved (fixed in 2.4.56-1)
sid: resolved (fixed in 2.4.56-1)
trixie: resolved (fixed in 2.4.56-1)
Apache
Apache httpd: CVE-2023-27522
vendor_apache·CVSS 7.5
CVE-2023-27522 Apache httpd: CVE-2023-27522
Apache httpd: CVE-2023-27522
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. Acknowledgements: finder: Dimas Fariski Setyawan Putra (nyxsorcerer) Reported to security team 2023-01-29 fixed by r1908094 in 2.4.x 2023-03-07 Update 2.4.56 released 2023-03-07 Affects 2.4.30 through 2.4.55
Severity: moderate
Affected versions: 2.4.55.
No detection rules found.
No public exploits indexed.
HackerOne
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
hackerone·2023-03-23·CVSS 7.5
CVE-2023-27522 [HIGH] Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)
#Summary
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2023-27522
## Impact
The response headers can be truncated, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.
Special characters in
Bugzilla
CVE-2023-27522 httpd: mod_proxy_uwsgi HTTP response splitting
bugzilla·2023-03-07·CVSS 7.5
CVE-2023-27522 [HIGH] CVE-2023-27522 httpd: mod_proxy_uwsgi HTTP response splitting
CVE-2023-27522 httpd: mod_proxy_uwsgi HTTP response splitting
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
References:
https://httpd.apache.org/security/vulnerabilities_24.html
https://www.openwall.com/lists/oss-security/2023/03/07/2
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 2176720]
---
Is there a timeline for when this will be patched in RHEL9?
---
We will probably fix it in the next RHEL-9 release.(In reply to ryan.brothers from comment #4)
> Is there a timeline for when this will be patched in RHEL9?
We will probably fix it in the n
https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2023/04/msg00028.htmlhttps://security.gentoo.org/glsa/202309-01https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2023/04/msg00028.htmlhttps://security.gentoo.org/glsa/202309-01
2023-03-07
Published