CVE-2024-42516: Apache HTTP Server
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
Affected products
- Apache HTTP Server: from 2.4.0, before 2.4.64 (fixed in 2.4.64)
Published 2025-07-10. Last modified 2026-06-17.