Apache2: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being…
Prior to Apache HTTP Server 2.4.55, a vulnerability exists where a malicious backend can cause response headers to be truncated early. This truncation results in some headers being included in the response body rather than being processed as headers. Consequently, security-related headers may not be interpreted by the client, potentially weakening security controls.
AI Analysis
Technical Summary
Apache HTTP Server versions prior to 2.4.55 are vulnerable to a flaw where a malicious backend can cause early truncation of response headers. This causes some headers to be incorporated into the response body instead of being recognized as headers by the client. If these headers serve security purposes, their omission from the header section can reduce the effectiveness of security mechanisms relying on those headers.
Potential Impact
The vulnerability impacts the integrity of HTTP response headers by truncating them prematurely, which can cause security headers to be ignored by clients. This may weaken client-side security enforcement that depends on those headers. There is no direct confidentiality or availability impact reported. No known exploits in the wild have been documented.
Mitigation Recommendations
A fix is available in Apache HTTP Server version 2.4.55. Users should upgrade to version 2.4.55 or later to remediate this issue. Patch status is confirmed by the version cutoff. Until upgraded, administrators should be aware of the risk posed by malicious backends manipulating response headers.
Apache2: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being…
Description
Prior to Apache HTTP Server 2.4.55, a vulnerability exists where a malicious backend can cause response headers to be truncated early. This truncation results in some headers being included in the response body rather than being processed as headers. Consequently, security-related headers may not be interpreted by the client, potentially weakening security controls.
CVSS v3.1
Score 5.3medium
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm9?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache HTTP Server versions prior to 2.4.55 are vulnerable to a flaw where a malicious backend can cause early truncation of response headers. This causes some headers to be incorporated into the response body instead of being recognized as headers by the client. If these headers serve security purposes, their omission from the header section can reduce the effectiveness of security mechanisms relying on those headers.
Potential Impact
The vulnerability impacts the integrity of HTTP response headers by truncating them prematurely, which can cause security headers to be ignored by clients. This may weaken client-side security enforcement that depends on those headers. There is no direct confidentiality or availability impact reported. No known exploits in the wild have been documented.
Mitigation Recommendations
A fix is available in Apache HTTP Server version 2.4.55. Users should upgrade to version 2.4.55 or later to remediate this issue. Patch status is confirmed by the version cutoff. Until upgraded, administrators should be aware of the risk posed by malicious backends manipulating response headers.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2022-37436
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a61512c9c2644c7f8da7087
Added to database: 07/22/2026, 23:24:28 UTC
Last enriched: 07/23/2026, 00:03:25 UTC
Last updated: 09/10/2026, 19:36:47 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.