cbcvebase.
CVE-2026-33523
published 2026-05-04

CVE-2026-33523: HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.672.4.67
apachehttpd
apache_software_foundationapache_http_server2.4.0 – 2.4.66
httpd_2.4httpd
ubuntuapache2