CVE-2022-22720: Apache HTTP Server
Critical severity, CVSS 9.8. EPSS: 28.2% chance of exploitation in the next 30 days.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Affected products
- Apache HTTP Server: up to and including 2.4.52
- Apple Mac OS X: version 10.15.7 only
- Apple macOS: before 10.15.7 (fixed in 10.15.7); from 11.0, before 11.6.6 (fixed in 11.6.6); from 12.0, up to and including 12.4
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 34 only; version 35 only; version 36 only
- Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle ZFS Storage Appliance Kit: version 8.8 only
Published 2022-03-14. Last modified 2026-06-17.