HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.
Users are recommended to upgrade to version 2.4.64, which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade httpd-toolsUpgrade mod_luaUpgrade httpdUpgrade httpd-coreUpgrade httpd-develUpgrade mod_ldapUpgrade mod_sessionUpgrade httpd-filesystemUpgrade mod_proxy_htmlUpgrade mod_http2Upgrade mod_sslUpgrade mod_mdUpgrade httpd-manual | Jul 21, 2026 | Jul 20, 2026 |
| Alpine Linux | — | Upgrade apache2 | Aug 8, 2025 | Jul 10, 2025 |
| Amazon Linux Ami 2 | — | Upgrade mod_sslUpgrade mod_sessionUpgrade mod_ldapUpgrade httpd-develUpgrade httpd-filesystemUpgrade httpd-debuginfoUpgrade mod_mdUpgrade httpdUpgrade mod_proxy_htmlUpgrade httpd-toolsUpgrade httpd-manual | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade mod_proxy_html-debuginfoUpgrade httpdUpgrade httpd-debuginfoUpgrade httpd-debugsourceUpgrade httpd-manualUpgrade httpd-coreUpgrade mod_lua-debuginfoUpgrade mod_ldapUpgrade httpd-tools-debuginfoUpgrade mod_sessionUpgrade mod_session-debuginfoUpgrade mod_sslUpgrade httpd-core-debuginfoUpgrade mod_proxy_htmlUpgrade mod_ssl-debuginfoUpgrade mod_luaUpgrade mod_ldap-debuginfoUpgrade httpd-develUpgrade httpd-toolsUpgrade httpd-filesystem | Aug 5, 2025 | Jul 14, 2025 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 18, 2025 | Jul 10, 2025 |
| Debian | — | Upgrade apache2 | Jul 14, 2025 | Jul 10, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 22, 2025 |
| Freebsd | — | Upgrade apache24 | Jul 13, 2025 | Jul 11, 2025 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Aug 16, 2026 | Aug 13, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade httpdUpgrade mod_sslUpgrade httpd-filesystemUpgrade httpd-tools | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade httpd-filesystemUpgrade httpd-toolsUpgrade mod_sslUpgrade httpd | Oct 14, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade httpd-filesystemUpgrade mod_sslUpgrade httpd-toolsUpgrade httpd | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade httpd-filesystemUpgrade mod_sslUpgrade httpd-toolsUpgrade httpd | Oct 24, 2025 | Oct 10, 2025 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.29 or laterApply IBM HTTP Server Interim Fix PH67153Apply IBM HTTP Server version 9.0.5.25 or later | Mar 25, 2026 | Aug 12, 2025 |
| Redhat_linux | — | Upgrade httpdUpgrade httpd-core-debuginfoUpgrade mod_ssl-debuginfoUpgrade mod_proxy_htmlUpgrade mod_mdNo solution existsUpgrade mod_luaUpgrade httpd-tools-debuginfoUpgrade mod_http2-debuginfoUpgrade httpd-toolsUpgrade httpd-develUpgrade mod_md-debugsourceUpgrade mod_session-debuginfoUpgrade httpd-coreUpgrade mod_sslUpgrade mod_ldap-debuginfoUpgrade mod_http2-debugsourceUpgrade httpd-filesystemUpgrade mod_sessionUpgrade httpd-debuginfoUpgrade mod_ldapUpgrade httpd-manualUpgrade httpd-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_lua-debuginfoUpgrade mod_http2Upgrade mod_md-debuginfo | Jul 15, 2025 | Jul 10, 2025 |
| Rocky_linux | — | Upgrade mod_sslUpgrade httpdUpgrade mod_md-debugsourceUpgrade mod_lua-debuginfoUpgrade httpd-develUpgrade mod_mdUpgrade mod_http2-debuginfoUpgrade httpd-tools-debuginfoUpgrade mod_luaUpgrade mod_md-debuginfoUpgrade mod_sessionUpgrade httpd-debuginfoUpgrade httpd-toolsUpgrade mod_http2-debugsourceUpgrade mod_ldap-debuginfoUpgrade mod_session-debuginfoUpgrade mod_http2Upgrade mod_ssl-debuginfoUpgrade httpd-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_ldapUpgrade httpd-core-debuginfoUpgrade mod_proxy_htmlUpgrade httpd-core | Jul 10, 2026 | Jul 7, 2026 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2-tls13-docUpgrade apache2-develUpgrade apache2-manualUpgrade apache2Upgrade apache2-preforkUpgrade apache2-utilsUpgrade apache2-tls13-workerUpgrade apache2-tls13-example-pagesUpgrade apache2-tls13Upgrade apache2-eventUpgrade apache2-workerUpgrade apache2-docUpgrade apache2-tls13-develUpgrade apache2-tls13-utilsUpgrade apache2-tls13-prefork | Dec 5, 2025 | Jul 31, 2025 |
| Ubuntu | — | Upgrade apache2Upgrade apache2 (Ubuntu Pro) | Jul 17, 2025 | Jul 10, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 11, 2025 | Jul 10, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub