HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
We have discovered 496,000 live websites that are affected by CVE-2023-27522.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 496,000 live websites (18% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 21 versions ( 18% of all versions) |
| 147,242 websites | |
| 58,487 websites | |
| 26,242 websites | |
| 23,386 websites | |
| 19,668 websites | |
| 18,547 websites | |
| 18,303 websites | |
| 16,723 websites | |
| 12,395 websites | |
| 12,389 websites |
| .com | 171,906 websites |
| .de | 31,462 websites |
| .org | 25,031 websites |
| .net | 19,359 websites |
| .it | 17,799 websites |
| .pl | 16,511 websites |
| .ru | 15,289 websites |
| .jp | 13,762 websites |
| .co.uk | 10,794 websites |
| .nl | 10,156 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ****.*********.net | *,*** | ||
| ******.*****.gov | *,*** | ||
| *************.com | *,*** | ||
| *******.*******.pl | *,*** | ||
| ******.org | *,*** | ||
| ***.**.uk | *,*** |
FAQ