Sceawere
Vulnerability Detail
CVE-2026-63718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache HTTP Server Request Smuggling
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T17:17:30.040Z",
"pubdate": "2026-10-01T17:17:30.040Z",
"executiveSummary": "This vulnerability involves an HTTP Request/Response Smuggling flaw within the Apache HTTP Server, specifically manifesting when using the mod_proxy_uwsgi module.\nThe issue arises from the inconsistent interpretation of HTTP headers between the proxy component and the backend uwsgi server, specifically concerning the handling of the 'Transfer-Encoding' header in uwsgi responses.\nAffected versions range from 2.4.30 through 2.4.68.\nAn attacker capable of influencing the response from a backend uwsgi server can exploit this discrepancy to manipulate the communication stream between the proxy and the client.\nThis can lead to severe security implications, including the potential for unauthorized data access, cache poisoning, or bypassing security controls implemented at the proxy layer.\nThe vulnerability effectively allows for the desynchronization of the request/response pipeline, where one response is misinterpreted as the beginning of another, potentially exposing sensitive data from subsequent requests to an unauthorized party.\nExploitation requires the attacker to control the backend uwsgi source or interact with an upstream environment that allows for malicious response injection.",
"technicalDetails": "The vulnerability is localized within the mod_proxy_uwsgi module of the Apache HTTP Server. It occurs due to a failure to properly sanitize or reconcile the 'Transfer-Encoding' header when parsing responses received from an upstream uwsgi server.\nHTTP Request/Response Smuggling relies on discrepancies in how different components of an HTTP pipeline—in this case, the Apache proxy and the downstream uwsgi infrastructure—interpret the boundaries of HTTP messages.\nWhen a backend uwsgi server sends a specially crafted response containing conflicting or ambiguous 'Transfer-Encoding' instructions, the Apache proxy may fail to accurately determine the end of the response body.\nThe exploitation flow proceeds as follows: An attacker sends a legitimate-looking request to the Apache proxy. The proxy forwards this request to the backend uwsgi process. The attacker, having achieved influence over the uwsgi backend, triggers a response that utilizes a crafted 'Transfer-Encoding' header designed to confuse the proxy's parsing logic.\nBecause the proxy interprets the message boundaries differently than the client or internal downstream buffers, the proxy may believe the response has terminated prematurely or continues unexpectedly.\nThis desynchronization allows the proxy to inadvertently associate 'leftover' data from the smuggled response with a subsequent, unrelated client request. If the smuggled data contains sensitive information or partial HTTP headers, it may be prepended to the response of the next user's request.\nThis results in information disclosure, where a victim receives portions of another user's session data, or in more complex scenarios, the manipulation of the proxy's internal request handling, potentially leading to unauthorized command execution or cross-site scripting (XSS) vectors if the smuggled content is rendered by the client.\nThe vulnerability exists in all Apache HTTP Server versions from 2.4.30 through 2.4.68. It does not strictly require authentication to the proxy, as the desynchronization happens during the standard request/response cycle, although successful manipulation of the backend response is a prerequisite for exploitation."
}