Impact
Inconsistent interpretation of HTTP requests by the mod_proxy_uwsgi module in Apache HTTP Server permits an attacker to send a crafted upstream uwsgi response that uses the Transfer‑Encoding header to confuse the server’s parsing logic. The server then mistakenly merges part of the upstream response with the downstream client response, allowing the attacker to inject or modify HTTP headers and body content. This can bypass authentication checks, alter data delivered to clients, and facilitate the delivery of malicious content, thereby compromising confidentiality and integrity. The weakness is identified as CWE‑444.
Affected Systems
Apache Software Foundation’s Apache HTTP Server versions 2.4.30 through 2.4.68 are affected. Any installation that enables mod_proxy_uwsgi and communicates with upstream uwsgi services may be vulnerable.
Risk and Exploitability
The flaw can be triggered remotely via a specially crafted uwsgi response, requiring no special local privileges. The CVSS score of 7.5 indicates a high severity, and the vulnerability is not listed in CISA KEV, with no EPSS score available. The potential for altering client responses and bypassing security controls indicates a severe risk. The attack could be executed by any external actor able to influence upstream uwsgi responses, making it a high‑impact vulnerability when applicable.
OpenCVE Enrichment