HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}


Thu, 10 Jul 2025 17:00:00 +0000

Type Values Removed Values Added
Description HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
Title Apache HTTP Server: HTTP response splitting
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-10T16:53:13.201Z

Updated: 2025-07-10T16:53:13.201Z

Reserved: 2024-08-03T18:37:28.141Z

Link: CVE-2024-42516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-07-10T17:15:45.343

Modified: 2025-07-10T17:15:45.343

Link: CVE-2024-42516

cve-icon Redhat

No data.