CVE-2023-27522: Apache HTTP Server

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.

Affected products

  • Apache HTTP Server: from 2.4.30, before 2.4.56 (fixed in 2.4.56)
  • Debian Debian Linux: version 10.0 only
  • Unbit Uwsgi: before 2.0.22 (fixed in 2.0.22)

Published 2023-03-07. Last modified 2026-06-17.