← Back to browse · API

CVE-2022-37436

Severity
MEDIUM
CVSS
5.3
EPSS
0.57941
Risk score
41.48
CISA KEV
No
PoC
Yes
Published
2023-01-17
Modified
2025-04-04
First seen
2026-08-07
Aliases
EUVD-2022-40063, GHSA-3F78-WQ4J-7VGR
Products
Apache Software Foundation:Apache HTTP Server 0 <2.4.55, linux, suse
Sources
packetstorm 6ed36f584bdbf7e8f0001469|CVE-2022-37436
euvd EUVD-2022-40063

Description

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

References