PT-2026-36815 · Apache+2 · Apache Http Server+2
Dawit Jeong
+2
·
Published
2026-03-05
·
Updated
2026-05-22
·
CVE-2026-33523
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.67
Description
HTTP response splitting occurs in multiple Apache HTTP Server modules when interacting with untrusted or compromised backend servers. This issue allows an attacker to split an HTTP response, potentially leading to cache poisoning or cross-site scripting.
Recommendations
Upgrade to version 2.4.67.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Linuxmint
Ubuntu