CVE-2012-3526: Thomas Eibner Mod Rpaf

Medium severity, CVSS 5.0. EPSS: 7% chance of exploitation in the next 30 days.

The reverse proxy add forward module (mod_rpaf) 0.5 and 0.6 for the Apache HTTP Server allows remote attackers to cause a denial of service (server or application crash) via multiple X-Forwarded-For headers in a request.

Affected products

Published 2012-09-05. Last modified 2026-06-16.