OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-63718

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Apache HTTP Server versions 2.4.30 to 2.4.68 are vulnerable to HTTP request/response smuggling due to inconsistent handling of Transfer-Encoding in mod_proxy_uwsgi. This flaw could allow an attacker to manipulate the server's response, potentially leading to unauthorized access or data leakage. Organizations using affected versions of Apache should prioritize patching to mitigate the risk associated with this vulnerability.

CVE
CVE-2026-63718
Severity
HIGH
CVSS
7.5
EPSS
0.32%
Apache

Original NVD Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

Related CVEs

Other vulnerabilities affecting the same vendor(s)