Vulnerabilities > Apache > Http Server > 2.4.54

DATE CVE VULNERABILITY TITLE RISK
2023-01-17 CVE-2022-36760 HTTP Request Smuggling vulnerability in Apache Http Server
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to.
network
high complexity
apache CWE-444
critical
9.0
2023-01-17 CVE-2022-37436 HTTP Response Splitting vulnerability in Apache Http Server
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body.
network
low complexity
apache CWE-113
5.3