CVE-2023-27522: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
Affected products
- Apache HTTP Server: from 2.4.30, before 2.4.56 (fixed in 2.4.56)
- Debian Debian Linux: version 10.0 only
- Unbit Uwsgi: before 2.0.22 (fixed in 2.0.22)
Published 2023-03-07. Last modified 2026-06-17.