← All CVEs

CVE-2022-37436

medium · 5.3

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

5.3
CVSS
61.0%
EPSS (exploit prob.)
99th
EPSS percentile
2023-01-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-113CWE-436

Affected products

VendorProductAffected versions
apachehttp_server< 2.4.55

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-37436