CVE-2023-27522

Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting

HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.


We have discovered 496,000 live websites that are affected by CVE-2023-27522.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains496,000 live websites (18% of Apache install base)
Vulnerable Versions
  • from 2.4.30 through 2.4.55
Vulnerable Versions Count21 versions ( 18% of all versions)


Common Weakness Enumeration

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')



Details

  • Published - Mar 7, 2023
  • Updated - Feb 13, 2025

Credits

  • Dimas Fariski Setyawan Putra (nyxsorcerer) (finder)

Website Distribution by Country

Number of websites using CVE-2023-27522
United States147,242 websites



Germany58,487 websites
France26,242 websites
Japan23,386 websites
Italy19,668 websites
Poland18,547 websites
GB18,303 websites
Russia16,723 websites
Netherlands12,395 websites
Canada12,389 websites

Website Distribution by TLD

Number of websites using CVE-2023-27522
.com171,906 websites
.de31,462 websites
.org25,031 websites
.net19,359 websites
.it17,799 websites
.pl16,511 websites
.ru15,289 websites
.jp13,762 websites
.co.uk10,794 websites
.nl10,156 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-27522

Top websites that are affected by CVE-2023-27522. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
****.*********.net GB*,***
******.*****.gov United States*,***
*************.com France*,***
*******.*******.pl Poland*,***
******.org United States*,***
***.**.uk GB*,***
See full domain list

FAQ

CVE-2023-27522 is Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Apache
A total of 496,000 websites have been identified as vulnerable to CVE-2023-27522, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2023-27522 vulnerability.
Apache versions up to and including 2.4.55 are vulnerable to CVE-2023-27522.