Apache HTTP Server HTTP Response Splitting Vulnerability

Vulnerability

A moderate severity HTTP response splitting vulnerability has been identified in Apache HTTP Server versions 2.4.0 prior to 2.4.63. This vulnerability allows an attacker to manipulate the Content-Type response headers of applications hosted or proxied by the server, creating a split in the HTTP response. The issue arises from improper input validation, which can be exploited by malicious backend generators or content.

Impact

Exploitation of this vulnerability can lead to HTTP response splitting, allowing for HTTP desynchronization attacks. This could be used to bypass security controls, such as authentication or access restrictions, and potentially poison caches in proxying scenarios.

Remediation

Users are advised to upgrade to Apache HTTP Server version 2.4.64, which addresses this vulnerability.

Added: Jul 10, 2025, 5:50 PM
Updated: Jul 10, 2025, 5:50 PM

Vulnerability Rating

Custom Algorithm
spread
9.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.