Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.



This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: HTTP Response Smuggling
Action: Immediate Patch
AI Analysis

Impact

Inconsistent interpretation of HTTP requests by the mod_proxy_uwsgi module in Apache HTTP Server permits an attacker to send a crafted upstream uwsgi response that uses the Transfer‑Encoding header to confuse the server’s parsing logic. The server then mistakenly merges part of the upstream response with the downstream client response, allowing the attacker to inject or modify HTTP headers and body content. This can bypass authentication checks, alter data delivered to clients, and facilitate the delivery of malicious content, thereby compromising confidentiality and integrity. The weakness is identified as CWE‑444.

Affected Systems

Apache Software Foundation’s Apache HTTP Server versions 2.4.30 through 2.4.68 are affected. Any installation that enables mod_proxy_uwsgi and communicates with upstream uwsgi services may be vulnerable.

Risk and Exploitability

The flaw can be triggered remotely via a specially crafted uwsgi response, requiring no special local privileges. The CVSS score of 7.5 indicates a high severity, and the vulnerability is not listed in CISA KEV, with no EPSS score available. The potential for altering client responses and bypassing security controls indicates a severe risk. The attack could be executed by any external actor able to influence upstream uwsgi responses, making it a high‑impact vulnerability when applicable.

Generated by OpenCVE AI on October 1, 2026 at 22:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache HTTP Server to version 2.4.69 or later, which includes a fix for the mod_proxy_uwsgi transfer‑encoding handling issue.
  • If an upgrade is not immediately possible, disable the mod_proxy_uwsgi module or remove it from the configuration to prevent the smuggling path.
  • If the module must remain enabled, restrict forwarding of uwsgi responses to trusted upstream peers and monitor for anomalous Transfer‑Encoding usage in upstream traffic.

Generated by OpenCVE AI on October 1, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache http Server
Vendors & Products Apache
Apache http Server

Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
Title Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
Weaknesses CWE-444
References

Subscriptions

Apache Http Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T20:09:32.103Z

Reserved: 2026-07-17T19:48:18.493Z

Link: CVE-2026-63718

cve-icon Vulnrichment

Updated: 2026-10-01T20:09:32.103Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:30.040

Modified: 2026-10-01T21:17:23.990

Link: CVE-2026-63718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:15:13Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')