← All CVEs

CVE-2022-26377

high · 7.5

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.

7.5
CVSS
21.1%
EPSS (exploit prob.)
97th
EPSS percentile
2022-06-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses

CWE-444

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, < 2.4.54
fedoraprojectfedora35
fedoraprojectfedora36
netappclustered_data_ontapall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-26377