CVE-2026-33523CWE-443
Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
Medium · published May 4, 2026
What it is
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.
This issue affects Apache HTTP Server: from through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
The record
Technical detail
- CVSS v3.1
- 6.5 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00436 · 36.6th percentile
- Weakness
- CWE-443 · DEPRECATED: HTTP response splitting
- Published
- 2026-05-04T14:40Z
EPSS history
Timeline