Apache · Apache Http Server · CVE-2022-26377
**Name of the Vulnerable Software and Affected Versions**
Apache HTTP Server versions 2.4.53 and prior versions
**Description**
The issue is related to the inconsistent interpretation of HTTP requests, also known as 'HTTP Request Smuggling', in the mod proxy ajp module of the Apache HTTP Server. This allows an attacker to smuggle requests to the AJP server it forwards requests to. The exploitation of this issue can enable a remote attacker to send a specially crafted HTTP request to the server and redirect requests to the AJP server. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
**Recommendations**
For Apache HTTP Server versions 2.4.53 and prior versions, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.