AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-37436

MEDIUM · CVSS 5.3 EPSS 57.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-37436
Severity
MEDIUM
CVSS
5.3
EPSS
57.94%
Apache

Original NVD Description

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.