HTTP Request Response Smuggling Vulnerability in Apache HTTP Server
CVE-2026-63718

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-63718?

The Apache HTTP Server is susceptible to a response smuggling vulnerability caused by inconsistent interpretation of crafted HTTP requests. This vulnerability arises through the 'mod_proxy_uwsgi' module when processing uwsgi responses that manipulate the Transfer-Encoding header. Attackers could exploit this flaw to smuggle malicious requests, potentially leading to unauthorized access or data leakage. The affected versions range from 2.4.30 to 2.4.68, necessitating prompt remedial action from users of the server.

Affected Version(s)

Apache HTTP Server 2.4.30 <= 2.4.68

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qing Xu
.