Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
We have discovered 1,523,343 live websites that are affected by CVE-2022-37436.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 1,523,343 live websites (54% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 106 versions ( 89% of all versions) |
| 408,031 websites | |
| 156,341 websites | |
| 111,995 websites | |
| 79,393 websites | |
| 72,964 websites | |
| 60,558 websites | |
| 50,879 websites | |
| 47,201 websites | |
| 41,277 websites | |
| 37,827 websites |
| .com | 600,149 websites |
| .de | 98,920 websites |
| .org | 65,526 websites |
| .net | 60,587 websites |
| .ru | 52,808 websites |
| .it | 44,615 websites |
| .nl | 35,100 websites |
| .cz | 34,251 websites |
| .jp | 28,530 websites |
| .pl | 25,744 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| *****.***********.com | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ******************.com | *,*** | ||
| ****.*********.net | *,*** | ||
| *******.org | *,*** |
FAQ