{"schema_version":"1.9.0","id":"CVE-2023-27522","published":"2023-03-07T15:09:30.122Z","modified":"2026-08-12T03:51:35.731758243Z","aliases":["BIT-apache-2023-27522","GHSA-vcph-37mh-fqrh","PYSEC-2026-1058"],"related":["ALSA-2023:5050","ALSA-2023:6403","SUSE-SU-2023:0764-1","SUSE-SU-2023:0799-1","SUSE-SU-2023:1573-1","SUSE-SU-2023:1658-1","SUSE-SU-2026:2686-1","openSUSE-SU-2024:12776-1","openSUSE-SU-2024:13346-1"],"summary":"Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting","details":"HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.\n\nSpecial characters in the origin response header can truncate/split the response forwarded to the client.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/httpd","events":[{"introduced":"3fe4a02b4936b73a10009ac8ea2c742730ccbe42"},{"fixed":"7e1212844f3100d90aea80d4fcd1621a17166a73"}],"database_specific":{"cpe":"cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.30"},{"fixed":"2.4.56"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27522.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/unbit/uwsgi","events":[{"introduced":"0"},{"fixed":"e7d3eda13189ed4f70762f4010b77849dc707f3d"}],"database_specific":{"cpe":"cpe:2.3:a:unbit:uwsgi:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.0.22"}],"source":"CPE_RANGE"}}],"versions":["2.0.21","2.0.20","2.0.19","2.0.18","2.0.17.1","2.0.17","2.0.16","2.0.15","2.0.14","2.0.13.1","2.0.13","2.0.12","2.0.11.2","2.0.10","2.0.11.1","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5.1","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0","2.0-rc1","1.9.21.1","1.9.21","1.9.19","1.9.18.1","1.9.17.1","1.9.17","1.9.16","1.9.15","1.9.14","1.9.13","1.9.12","1.9.11","1.9.10","1.9.9","1.9.8","1.9.7","1.9.6","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9","1.9-rc2","1.9-rc1","1.4-rc2","1.4-rc1","1.3","1.3-rc4","1.3-rc3","1.3-rc2","1.2","1.2-rc2","1.2-rc1","1.1","1.1-rc4","1.1-rc3","1.1-rc2","1.1-rc1","1.0.1","1.0","1.0-rc10","1.0-rc9","1.0-rc8","1.0-rc7","1.0-rc6","1.0-rc5","1.0-rc4","1.0-rc3","1.0-rc2","1.0-rc1","0.9.9","0.9.9-rc2","0.9.9-rc1","0.9.9-beta1","0.9.8.3","0.9.8.2","0.9.8.1","0.9.8","0.9.8-rc4","0.9.8-rc3","0.9.8-rc2","0.9.8-rc1","0.9.7.2","0.9.7.1","0.9.7","0.9.7-rc3","0.9.7-rc2","0.9.7-rc1","0.9.7-beta1","0.9.6.2","0.9.6.1","0.9.6","0.9.6-rc2","0.9.6-rc1","0.9.5.1","0.9.5","0.9.5rc2","0.9.5rc1","0.9.5beta1","no_server_mode"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27522.json"}}],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27522.json"},{"type":"ADVISORY","url":"https://httpd.apache.org/security/vulnerabilities_24.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27522"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202309-01"}],"database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-444"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27522.json","unresolved_ranges":[{"extracted_events":[{"introduced":"2.4.30"},{"last_affected":"2.4.55"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"2.4.30"},{"fixed":"2.4.55"}],"source":"DESCRIPTION"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}