Inconsistent interpretation of HTTP requests in Apache HTTP Server - CVE-2026-63718
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP response smuggling.
The vulnerability exists due to inconsistent interpretation of HTTP responses in mod_proxy_uwsgi when processing a crafted uwsgi response with a Transfer-Encoding header. A remote attacker can send a crafted uwsgi response to perform HTTP response smuggling.