HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
History

Tue, 29 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache http Server
CPEs cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Vendors & Products Apache http Server

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}

epss

{'score': 0.0005}


Tue, 15 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Mon, 14 Jul 2025 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-113
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}

threat_severity

Moderate


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00037}


Thu, 10 Jul 2025 17:00:00 +0000

Type Values Removed Values Added
Description HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
Title Apache HTTP Server: HTTP response splitting
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-10T16:53:13.201Z

Updated: 2025-07-15T19:56:51.797Z

Reserved: 2024-08-03T18:37:28.141Z

Link: CVE-2024-42516

cve-icon Vulnrichment

Updated: 2025-07-11T16:07:09.240Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-10T17:15:45.343

Modified: 2025-07-29T15:16:31.397

Link: CVE-2024-42516

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-14T07:13:28Z

Links: CVE-2024-42516 - Bugzilla