CVE-2022-36760

Apache HTTP Server: mod_proxy_ajp Possible request smuggling

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.


We have discovered 1,455,451 live websites that are affected by CVE-2022-36760.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,455,451 live websites (46.13% of Apache install base)
Vulnerable Versions
  • from 2.4 through 2.4.54
Vulnerable Versions Count48 versions ( 32.65% of all versions)


Common Weakness Enumeration

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')



Details

  • Published - Jan 17, 2023
  • Updated - Feb 13, 2025

Credits

  • ZeddYu_Lu from Qi'anxin Research Institute of Legendsec at Qi'anxin Group (finder)

CVE-2022-36760 usage by Country

United States525,570 websites



Germany173,732 websites
France92,917 websites
Netherlands54,879 websites
Russia50,083 websites
Japan46,050 websites
Singapore44,029 websites
Italy35,331 websites
Czech Republic35,004 websites
Poland29,203 websites

CVE-2022-36760 usage by TLD

.com550,574 websites
.de102,261 websites
.org69,368 websites
.net57,739 websites
.ru44,031 websites
.nl43,318 websites
.it36,365 websites
.cz29,408 websites
.fr28,503 websites
.pl26,735 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-36760

Top websites that are affected by CVE-2022-36760. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.com United States***
*********.*************.se United States***
***********.org United States***
*********.net United States***
********.*********.com Singapore*,***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
See full domain list

FAQ

CVE-2022-36760 is Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Apache
A total of 1,455,451 websites have been identified as vulnerable to CVE-2022-36760, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2022-36760 vulnerability.
Apache versions before, and including, 2.4.54 are vulnerable to CVE-2022-36760.