CVE-2022-37436

Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.


We have discovered 1,523,343 live websites that are affected by CVE-2022-37436.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,523,343 live websites (54% of Apache install base)
Vulnerable Versions
  • from 0 through 2.4.55
Vulnerable Versions Count106 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')



Details

  • Published - Jan 17, 2023
  • Updated - Apr 4, 2025

Credits

  • Dimas Fariski Setyawan Putra (@nyxsorcerer) (finder)

Website Distribution by Country

Number of websites using CVE-2022-37436
United States408,031 websites



Germany156,341 websites
Taiwan111,995 websites
France79,393 websites
Japan72,964 websites
Russia60,558 websites
Italy50,879 websites
Netherlands47,201 websites
Czech Republic41,277 websites
Singapore37,827 websites

Website Distribution by TLD

Number of websites using CVE-2022-37436
.com600,149 websites
.de98,920 websites
.org65,526 websites
.net60,587 websites
.ru52,808 websites
.it44,615 websites
.nl35,100 websites
.cz34,251 websites
.jp28,530 websites
.pl25,744 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-37436

Top websites that are affected by CVE-2022-37436. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*****.***********.com Canada***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******************.com United States*,***
****.*********.net GB*,***
*******.org United States*,***
See full domain list

FAQ

CVE-2022-37436 is Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in Apache
A total of 1,523,343 websites have been identified as vulnerable to CVE-2022-37436, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2022-37436 vulnerability.
Apache versions up to 2.4.55 are vulnerable to CVE-2022-37436.
CVE-2022-37436 is resolved in version 2.4.55 of Apache.