CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
Published Oct 1, 2026
·Updated
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via modproxyuwsgi and a crafted uwsgi response with Transfer-Encoding.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.
Affected Software
1 affected component
Apache HTTP Server>=2.4.30<=2.4.68
Event History
Oct 1, 2026
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Apache HTTP Server versions 2.4.30 through 2.4.68 are affected when mod_proxy_uwsgi is used. The issue involves processing a crafted uWSGI response containing Transfer-Encoding.
2
What must an attacker be able to do to exploit it?
An attacker needs to cause or control a crafted response from a uWSGI backend that is proxied through mod_proxy_uwsgi. The provided information does not establish exploitation through ordinary client requests alone.