← Back to CVE List
CVE-2026-63718NVD
Vulnerability Summary
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Apache Http Server >= 2.4.30 and < 2.4.69
- Apache Http Server 2.4.69