CVE-2023-38709
HIGH7.3EPSS 4.4%Apache HTTP Server: HTTP response splitting
Published: 4/4/2024Modified: 4/28/2026
Description
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
Affected packages (3)
- Alpine/apache2from 0, < 2.4.59-r0
- Bitnami/apachefrom 0, < 2.4.59
- Debian/apache2from 0, < 2.4.59-1~deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
References (14)
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2023-38709
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2023-38709
- WEBhttp://seclists.org/fulldisclosure/2024/Jul/18
- WEBhttps://httpd.apache.org/security/vulnerabilities_24.html
- WEBhttps://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2023-38709
- WEBhttps://security.netapp.com/advisory/ntap-20240415-0013/
- WEBhttps://support.apple.com/kb/HT214119
- WEBhttp://www.openwall.com/lists/oss-security/2024/04/04/3
- WEBhttp://www.openwall.com/lists/oss-security/2025/07/10/2
- WEBhttp://www.openwall.com/lists/oss-security/2025/07/10/3