HTTP response splitting in Apache HTTP Server - CVE-2026-33523
Published: May 4, 2026
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to manipulate HTTP responses.
The vulnerability exists due to improper neutralization of CRLF sequences in multiple Apache HTTP Server modules when forwarding a backend status line. A remote attacker can supply a malicious backend response to manipulate HTTP responses.
Exploitation requires an untrusted or compromised backend server.