CVE-2026-33523CWE-443

Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line

Medium · published May 4, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
36.6
In the wild
Unconfirmed
What it is

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.

This issue affects Apache HTTP Server: from through 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00436 · 36.6th percentile
Weakness
CWE-443 · DEPRECATED: HTTP response splitting
Published
2026-05-04T14:40Z
EPSS history
Timeline
  • 04 MAY 14:40Z
    Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
    cvelistv5