CVE-2026-33523

Published: Mag 04, 2026 Last Modified: Mag 04, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers.

This issue affects Apache HTTP Server: from through 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

443

DEPRECATED: HTTP response splitting

Deprecated
Common Consequences
Applicable Platforms
All platforms may be affected
View CWE Details
https://httpd.apache.org/security/vulnerabilities_24.html