CVE-2016-5387: Apache HTTP Server

High severity, CVSS 8.1. EPSS: 55.7% chance of exploitation in the next 30 days.

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.

Affected products

  • Apache HTTP Server: from 2.2.0, up to and including 2.2.31; from 2.4.1, up to and including 2.4.23
  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 23 only; version 24 only
  • HP System Management Homepage: up to and including 7.5.5.0
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Communications User Data Repository: from 10.0.0, up to and including 12.4
  • Oracle Enterprise Manager Ops Center: version 12.2.2 only; version 12.3.2 only
  • Oracle Linux: version 5 only; version 6 only; version 7 only
  • Oracle Solaris: version 11.3 only
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only; version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.2 only; version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat JBoss Core Services: version 1.0 only
  • Red Hat JBoss Enterprise Web Server: version 2.0.0 only; version 3.0.0 only
  • Red Hat JBoss Web Server: version 2.1.0 only

Published 2016-07-19. Last modified 2026-06-17.