CVE-2016-8743: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 13.3% chance of exploitation in the next 30 days.

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

Affected products

  • Apache HTTP Server: from 2.2.0, up to and including 2.2.31; from 2.4.1, up to and including 2.4.23
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp Oncommand Unified Manager: affected versions not specified
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.3 only; version 7.4 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Server Tus: version 7.3 only; version 7.6 only; version 7.7 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
  • Red Hat JBoss Core Services: version 1.0 only

Published 2017-07-27. Last modified 2026-06-17.