CVE-2022-26377: mod_proxy_ajp: Possible request smuggling
An HTTP request smuggling vulnerability was found in the modproxyajp module of httpd. This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests.
Other sources
Apache HTTP Server is vulnerable to HTTP request smuggling, caused by an inconsistent Interpretation of HTTP Requests vulnerability in modproxyajp. An attacker could exploit this vulnerability to smuggle requests to the AJP server it forwards requests to.
— IBM
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in modproxyajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server 2.4 version 2.4.53 and prior versions.
References: https://httpd.apache.org/security/vulnerabilities24.html https://www.openwall.com/lists/oss-security/2022/06/08/2
— Red Hat
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in modproxyajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-26377?
CVE-2022-26377 is an HTTP request smuggling vulnerability found in the mod_proxy_ajp module of httpd.
How does the Inconsistent Interpretation of HTTP Requests (HTTP Request Smuggling) vulnerability affect Apache HTTP Server?
The vulnerability allows an attacker to smuggle requests to the AJP server that Apache HTTP Server forwards requests to.
Which versions of Apache HTTP Server are affected by CVE-2022-26377?
Apache HTTP Server versions 2.4.53 and prior are affected.
What is the severity level of CVE-2022-26377?
The severity level of CVE-2022-26377 is high, with a severity value of 7.5.
How can I fix the Inconsistent Interpretation of HTTP Requests (HTTP Request Smuggling) vulnerability in Apache HTTP Server?
To fix the vulnerability, update Apache HTTP Server to version 2.4.54 or later.