CVE-2023-38709
published 2024-04-04CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache…
PriorityP347high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
3.91%
89.2th percentile
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.59 | 2.4.59 |
| apache | http_server | >= 2.4.0 < 2.4.64 | 2.4.64 |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.63 | — |
| apple | macos | < 14.6 | 14.6 |
| apple | macos_sonoma | — | — |
| debian | apache2 | < apache2 2.4.59-1~deb12u1 (bookworm) | apache2 2.4.59-1~deb12u1 (bookworm) |
| debian | apache2 | < apache2 2.4.65-1~deb12u1 (bookworm) | apache2 2.4.65-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_httpd_2.4.58-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_httpd_2.4.61-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_httpd_2.4.58-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_httpd_2.4.59-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| netapp | ontap | — | — |
| netapp | ontap_tools | — | — |
| ubuntu | apache2 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.3HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
vendor_ubuntu7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server regression
vendor_ubuntu·2026-05-29·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server regression
Title: Apache HTTP Server regression
Summary: USN-8338-1 introduced a regression in Apache HTTP Server
USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update
introduced a regression that prevented mod_http2 from loading on Ubuntu
18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2026-05-28·CVSS 7.3
CVE-2023-38709 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
It was discovered that Apache HTTP Server incorrectly handled certain
response headers. An attacker could possibly use this issue to perform
HTTP response splitting attacks. This issue only affected Ubuntu 14.04
LTS. (CVE-2023-38709)
Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2
implementation did not properly reclaim memory when streams were reset by
clients. A remote attacker could possibly use this issue to cause Apache
HTTP Server to consume resources, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802)
Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly
handled certain response headers.
Red Hat
httpd: incomplete fix for CVE-2023-38709
vendor_redhat·2025-07-14·CVSS 7.3
CVE-2024-42516 [HIGH] CWE-20 httpd: incomplete fix for CVE-2023-38709
httpd: incomplete fix for CVE-2023-38709
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.
Users are recommended to upgrade to version 2.4.64, which fixes this issue.
A flaw was found in httpd. The response headers are not sanitized before an HTTP response is sent when a malicious backend can insert a Content-Type, Content-Encoding, or some other headers. These issues lead to HTTP response splitting. This CVE provides a "complete" fix for CVE-2023-38709.
Statement: This flaw is only exploitable by a malic
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-11-14
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontro
Apple
CVE-2023-38709: macOS Sonoma 14.6
vendor_apple·2024-07-29·CVSS 7.3
CVE-2023-38709 [HIGH] CVE-2023-38709: macOS Sonoma 14.6
Apple Security Update: About the security content of macOS Sonoma 14.6
Product: macOS Sonoma
Version: 14.6
CVE: CVE-2023-38709
Component: AirDrop
Impact: A file received from AirDrop may not have the quarantine flag applied
Description: This issue was addressed through improved state management.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-29·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6729-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuati
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-17·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-6729-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled en
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2024-04-11·CVSS 7.3
CVE-2024-27316 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to consume resources, leading
to a denial of service. (CVE-2024-27316)
Ins
Microsoft
Apache HTTP Server: HTTP response splitting
vendor_msrc·2024-04-09·CVSS 7.3
CVE-2023-38709 [HIGH] CWE-1284 Apache HTTP Server: HTTP response splitting
Apache HTTP Server: HTTP response splitting
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft
Red Hat
httpd: HTTP response splitting
vendor_redhat·2024-04-04·CVSS 7.3
CVE-2023-38709 [HIGH] CWE-444 httpd: HTTP response splitting
httpd: HTTP response splitting
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
A flaw was found in httpd. The response headers are not sanitized before an HTTP response is sent when a malicious backend can insert a Content-Type, Content-Encoding, or some other headers, resulting in an HTTP response splitting.
Statement: This flaw is only exploitable by a malicious backend or a malicious application, but may also affect forward proxy configurations.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to wid
Debian
CVE-2024-42516: apache2 - HTTP response splitting in the core of Apache HTTP Server allows an attacker who...
vendor_debian·2024·CVSS 7.3
CVE-2024-42516 [HIGH] CVE-2024-42516: apache2 - HTTP response splitting in the core of Apache HTTP Server allows an attacker who...
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
Scope: local
bookworm: resolved (fixed in 2.4.65-1~deb12u1)
bullseye: resolved (fixed in 2.4.65-1~deb11u1)
forky: resolved (fixed in 2.4.64-1)
sid: resolved (fixed in 2.4.64-1)
trixie: resolved (fixed in 2.4.64-1)
Debian
CVE-2023-38709: apache2 - Faulty input validation in the core of Apache allows malicious or exploitable ba...
vendor_debian·2023·CVSS 7.3
CVE-2023-38709 [HIGH] CVE-2023-38709: apache2 - Faulty input validation in the core of Apache allows malicious or exploitable ba...
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
Scope: local
bookworm: resolved (fixed in 2.4.59-1~deb12u1)
bullseye: resolved (fixed in 2.4.59-1~deb11u1)
forky: resolved (fixed in 2.4.59-1)
sid: resolved (fixed in 2.4.59-1)
trixie: resolved (fixed in 2.4.59-1)
GHSA
GHSA-5j7h-7m92-jgh4: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
ghsa_unreviewed·2025-07-10·CVSS 7.3
CVE-2024-42516 [HIGH] CWE-20 GHSA-5j7h-7m92-jgh4: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.
Users are recommended to upgrade to version 2.4.64, which fixes this issue.
OSV
CVE-2024-42516: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
osv·2025-07-10·CVSS 7.3
CVE-2024-42516 [HIGH] CVE-2024-42516: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
OSV
CVE-2024-42516: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
osv·2025-07-10·CVSS 7.3
CVE-2024-42516 [HIGH] CVE-2024-42516: HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications host
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.
Users are recommended to upgrade to version 2.4.64, which fixes this issue.
OSV
apache2 vulnerabilities
osv·2024-04-29·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-6729-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to cons
OSV
apache2 vulnerabilities
osv·2024-04-17·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-6729-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause th
OSV
apache2 vulnerabilities
osv·2024-04-11·CVSS 7.3
CVE-2023-38709 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
Orange Tsai discovered that the Apache HTTP Server incorrectly handled
validating certain input. A remote attacker could possibly use this
issue to perform HTTP request splitting attacks. (CVE-2023-38709)
Keran Mu and Jianjun Chen discovered that the Apache HTTP Server
incorrectly handled validating certain input. A remote attacker could
possibly use this issue to perform HTTP request splitting attacks.
(CVE-2024-24795)
Bartek Nowotarski discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled endless continuation frames. A remote attacker could
possibly use this issue to cause the server to consume resources, leading
to a denial of service. (CVE-2024-27316)
OSV
CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
osv·2024-04-04·CVSS 7.3
CVE-2023-38709 [HIGH] CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
OSV
CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
osv·2024-04-04·CVSS 7.3
CVE-2023-38709 [HIGH] CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
GHSA
GHSA-9fvf-9v35-97qv: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
ghsa_unreviewed·2024-04-04
CVE-2023-38709 [HIGH] CWE-1284 GHSA-9fvf-9v35-97qv: Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709
bugzilla·2025-06-24·CVSS 7.3
CVE-2024-42516 [HIGH] CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709
CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709
CVE-2024-42516 - this is the "complete" fix for the CVE-2023-38709 response
splitting issue. The patch issued upstream for CVE-2023-38709 did not fix the vulnerability.
HackerOne
moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709)
hackerone·2024-07-13·CVSS 7.3
CVE-2023-38709 [HIGH] moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709)
moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709)
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
###moderate: Apache HTTP Server: HTTP response splitting (CVE-2023-38709)
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58
Bugzilla
CVE-2023-38709 httpd: HTTP response splitting
bugzilla·2024-04-04·CVSS 7.3
CVE-2023-38709 [HIGH] CVE-2023-38709 httpd: HTTP response splitting
CVE-2023-38709 httpd: HTTP response splitting
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
References:
https://httpd.apache.org/security/vulnerabilities_24.html
https://svn.apache.org/viewvc?view=revision&revision=1916770
Discussion:
Created httpd tracking bugs for this issue:
Affects: fedora-all [bug 2273492]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:4197 https://access.redhat.com/errata/RHSA-2024:4197
---
When applying the patch for this issue it seems to entirely rewrite the /var/www/html folder and deletes its content using the below:
2.4.37-65.module+el8.10.0+21982+14717793
---
(In reply to athreadgill from comment #6)
> When ap
http://seclists.org/fulldisclosure/2024/Jul/18http://www.openwall.com/lists/oss-security/2024/04/04/3https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/https://lists.fedoraproject.org/archives/list/[email protected]/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/https://security.netapp.com/advisory/ntap-20240415-0013/https://support.apple.com/kb/HT214119http://seclists.org/fulldisclosure/2024/Jul/18http://www.openwall.com/lists/oss-security/2024/04/04/3http://www.openwall.com/lists/oss-security/2025/07/10/2http://www.openwall.com/lists/oss-security/2025/07/10/3https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/https://lists.fedoraproject.org/archives/list/[email protected]/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/https://security.netapp.com/advisory/ntap-20240415-0013/https://support.apple.com/kb/HT214119
2024-04-04
Published