HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.
This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.
Users are recommended to upgrade to version 2.4.64, which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade httpd-toolsUpgrade httpdUpgrade httpd-develUpgrade httpd-coreUpgrade mod_luaUpgrade mod_mdUpgrade mod_sessionUpgrade httpd-filesystemUpgrade httpd-manualUpgrade mod_proxy_htmlUpgrade mod_sslUpgrade mod_ldapUpgrade mod_http2 | Jul 21, 2026 | Jul 20, 2026 |
| Alpine Linux | — | Upgrade apache2 | Aug 8, 2025 | Jul 10, 2025 |
| Amazon Linux Ami 2 | — | Upgrade mod_proxy_htmlUpgrade httpd-manualUpgrade httpd-toolsUpgrade httpd-filesystemUpgrade httpd-debuginfoUpgrade mod_sessionUpgrade mod_mdUpgrade mod_sslUpgrade mod_ldapUpgrade httpd-develUpgrade httpd | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade httpdUpgrade mod_lua-debuginfoUpgrade httpd-core-debuginfoUpgrade mod_session-debuginfoUpgrade mod_ldapUpgrade mod_sessionUpgrade httpd-debugsourceUpgrade httpd-tools-debuginfoUpgrade httpd-manualUpgrade httpd-coreUpgrade httpd-debuginfoUpgrade mod_sslUpgrade mod_proxy_html-debuginfoUpgrade httpd-develUpgrade httpd-filesystemUpgrade httpd-toolsUpgrade mod_ssl-debuginfoUpgrade mod_ldap-debuginfoUpgrade mod_luaUpgrade mod_proxy_html | Aug 5, 2025 | Jul 14, 2025 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 18, 2025 | Jul 10, 2025 |
| Debian | — | Upgrade apache2 | Jul 14, 2025 | Jul 10, 2025 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 22, 2025 |
| Freebsd | — | Upgrade apache24 | Jul 13, 2025 | Jul 11, 2025 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Aug 16, 2026 | Aug 13, 2026 |
| Huawei Euleros 2_0_sp10 | — | Upgrade mod_sslUpgrade httpdUpgrade httpd-toolsUpgrade httpd-filesystem | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp11 | — | Upgrade httpd-filesystemUpgrade mod_sslUpgrade httpdUpgrade httpd-tools | Oct 14, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade httpdUpgrade httpd-toolsUpgrade mod_sslUpgrade httpd-filesystem | Nov 12, 2025 | Oct 10, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade httpd-toolsUpgrade httpdUpgrade mod_sslUpgrade httpd-filesystem | Oct 24, 2025 | Oct 10, 2025 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PH67153Apply IBM HTTP Server version 8.5.5.29 or laterApply IBM HTTP Server version 9.0.5.25 or later | Mar 25, 2026 | Aug 12, 2025 |
| Redhat_linux | — | No solution existsUpgrade mod_mdUpgrade mod_luaUpgrade httpd-core-debuginfoUpgrade httpdUpgrade mod_ssl-debuginfoUpgrade httpd-toolsUpgrade mod_proxy_htmlUpgrade mod_md-debugsourceUpgrade httpd-tools-debuginfoUpgrade httpd-develUpgrade mod_http2-debuginfoUpgrade mod_proxy_html-debuginfoUpgrade httpd-manualUpgrade mod_ldap-debuginfoUpgrade mod_sslUpgrade httpd-debugsourceUpgrade mod_sessionUpgrade mod_md-debuginfoUpgrade mod_http2Upgrade httpd-coreUpgrade mod_ldapUpgrade httpd-debuginfoUpgrade mod_lua-debuginfoUpgrade mod_session-debuginfoUpgrade mod_http2-debugsourceUpgrade httpd-filesystem | Jul 15, 2025 | Jul 10, 2025 |
| Rocky_linux | — | Upgrade mod_http2Upgrade mod_session-debuginfoUpgrade mod_ssl-debuginfoUpgrade httpd-coreUpgrade mod_proxy_htmlUpgrade httpd-core-debuginfoUpgrade httpd-toolsUpgrade mod_proxy_html-debuginfoUpgrade mod_ldapUpgrade httpd-debugsourceUpgrade mod_http2-debugsourceUpgrade mod_ldap-debuginfoUpgrade httpd-develUpgrade mod_luaUpgrade mod_lua-debuginfoUpgrade httpdUpgrade mod_md-debugsourceUpgrade httpd-tools-debuginfoUpgrade mod_http2-debuginfoUpgrade mod_sslUpgrade mod_mdUpgrade mod_sessionUpgrade mod_md-debuginfoUpgrade httpd-debuginfo | Jul 10, 2026 | Jul 7, 2026 |
| Suse | — | Upgrade apache2-tls13Upgrade apache2-workerUpgrade apache2-tls13-utilsUpgrade apache2-eventUpgrade apache2-tls13-example-pagesUpgrade apache2-tls13-develUpgrade apache2-docUpgrade apache2-tls13-workerUpgrade apache2-utilsUpgrade apache2-tls13-preforkUpgrade apache2-example-pagesUpgrade apache2Upgrade apache2-develUpgrade apache2-manualUpgrade apache2-preforkUpgrade apache2-tls13-doc | Dec 5, 2025 | Jul 31, 2025 |
| Ubuntu | — | Upgrade apache2Upgrade apache2 (Ubuntu Pro) | Jul 17, 2025 | Jul 10, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 11, 2025 | Jul 10, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub