CVE-2022-22720

CRITICAL9.8EPSS 27.5%

HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

Published: 3/14/2022Modified: 4/28/2026

Description

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (19)