CVE-2022-26377

NameCVE-2022-26377
DescriptionInconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
Debian Bugs1012513

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)buster, buster (security)2.4.38-3+deb10u7vulnerable
bullseye2.4.53-1~deb11u1vulnerable
bullseye (security)2.4.52-1~deb11u2vulnerable
bookworm, sid2.4.54-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2source(unstable)2.4.54-11012513

Notes

[bullseye] - apache2 <no-dsa> (Minor issue; can be fixed in point release)
[buster] - apache2 <no-dsa> (Minor issue; can be fixed in point release)
https://www.openwall.com/lists/oss-security/2022/06/08/2
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-26377
https://github.com/apache/httpd/commit/f7f15f3d8bfe3032926c8c39eb8434529f680bd4

Search for package or bug name: Reporting problems