Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).
A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table