CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
CVSS Details
- CVSS 3.1 Base Score: 3.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Sep 27, 2012 | Jan 25, 2008 |
| Apple Osx Apache | — | Upgrade macOS to the latest version | Dec 16, 2011 | Jan 24, 2008 |
| Centos_linux | — | Upgrade mod_sslUpgrade httpd-develUpgrade httpdUpgrade httpd-manual | Dec 1, 2016 | Jan 24, 2008 |
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 28, 2015 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jan 24, 2008 |
| Oracle_linux | — | Upgrade httpd-develUpgrade mod_sslUpgrade httpdUpgrade httpd-manual | Oct 16, 2024 | Jan 25, 2008 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-example-pagesUpgrade apache2-workerUpgrade apache2Upgrade apache2-docUpgrade apache2-utils | Dec 12, 2013 | Jan 24, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub