HTTP Response Splitting Vulnerability in Apache HTTP Server
CVE-2024-42516

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 July 2025

What is CVE-2024-42516?

A vulnerability in the core of Apache HTTP Server permits attackers to exploit HTTP response splitting by manipulating the Content-Type response headers. This flaw allows unauthorized parties to split a server's HTTP responses, potentially leading to various attacks, including cross-site scripting (XSS) or cache poisoning. Despite previous mentions of a related issue in CVE-2023-38709, the patch in Apache HTTP Server version 2.4.59 did not adequately resolve the exploit. Users are strongly advised to upgrade to version 2.4.64, which rectifies this vulnerability and enhances server security.

Affected Version(s)

Apache HTTP Server 2.4.0 <= 2.4.63

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-42516 : HTTP Response Splitting Vulnerability in Apache HTTP Server