{"id":"CVE-2023-27522","title":"httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)","summary":"An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-113","vendor":"Red Hat","product":"Red Hat Enterprise Linux AppStream EUS (v.8.6)","affected":["enterprise_linux 6","enterprise_linux 7","jboss_enterprise_application_platform 6","jboss_core_services_on_rhel_7_server","jboss_core_services_on_rhel 8","enterprise_linux_appstream_eus_v_8_6","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_2","enterprise_linux_appstream_v_9"],"patched":["jboss_core_services_on_rhel_7_server","jboss_core_services_on_rhel 8","enterprise_linux_appstream_eus_v_8_6","enterprise_linux_appstream_v_8","enterprise_linux_appstream_eus_v_9_2","enterprise_linux_appstream_v_9"],"published":"2023-03-07","updated":"2026-09-21","sourceUpdated":"2026-09-21T05:44:31+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-27522"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2176211"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-27522"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27522"},{"url":"https://httpd.apache.org/security/vulnerabilities_24.html"},{"url":"https://access.redhat.com/errata/RHSA-2023:4629"},{"url":"https://access.redhat.com/errata/RHSA-2023:5049"},{"url":"https://access.redhat.com/errata/RHSA-2023:5050"},{"url":"https://access.redhat.com/errata/RHSA-2024:4504"},{"url":"https://access.redhat.com/errata/RHSA-2023:6403"},{"url":"https://github.com/apache/httpd/commit/d753ea76b5972a85349b68c31b59d04c60014f2d"},{"url":"https://github.com/unbit/uwsgi/commit/58ee1df31fa9e9af106aaeabb82374c36b433822"},{"url":"https://github.com/unbit/uwsgi/commit/acb03530aaaeaa810f28a5b64da619525940f569"},{"url":"https://github.com/unbit/uwsgi"},{"url":"https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html"},{"url":"https://security.gentoo.org/glsa/202309-01"},{"url":"https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.22.html"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.02134,"epssPercentile":0.81211,"aliases":["GHSA-vcph-37mh-fqrh","BIT-apache-2023-27522","PYSEC-2026-1058"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:53.304Z","slug":"CVE-2023-27522","body":"## Overview\n\nAn HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.\n\n## Vendor advisories\n\n- **RHSA-2023:4629** · Red Hat · fixed in: Red Hat JBoss Core Services on RHEL 7 Server, Red Hat JBoss Core Services on RHEL 8 · released 2023-08-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:4629)\n- **RHSA-2023:5049** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.6) · released 2023-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:5049)\n- **RHSA-2023:5050** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2023-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:5050)\n- **RHSA-2024:4504** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.2) · released 2024-07-11 · [advisory](https://access.redhat.com/errata/RHSA-2024:4504)\n- **RHSA-2023:6403** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6403)\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Enterprise Application Platform 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Enterprise Application Platform 6 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json)\n\n**httpd: mod_proxy_uwsgi HTTP response splitting** — rated Moderate by Red Hat. Released 2023-03-07, updated 2026-09-21.\n\nAffected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat JBoss Enterprise Application Platform 6\n\nFixed:\n\n- Red Hat JBoss Core Services on RHEL 7 Server\n- Red Hat JBoss Core Services on RHEL 8\n- Red Hat Enterprise Linux AppStream EUS (v.8.6)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream EUS (v.9.2)\n- Red Hat Enterprise Linux AppStream (v. 9)\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat JBoss Enterprise Application Platform 6\n\nNot affected:\n\n- Red Hat JBoss Core Services on RHEL 7 Server\n- Red Hat JBoss Core Services on RHEL 8\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Red Hat Software Collections\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:4629\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the updated packages, the httpd daemon will be restarted automatically. https://access.redhat.com/errata/RHSA-2023:5049\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nAfter installing the updated packages, the httpd daemon will be restarted automatically. https://access.redhat.com/errata/RHSA-2023:5050\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2023-27522)\n\nAffected packages:\n\n- `uwsgi < 2.0.22`\n\nPatched in:\n\n- `uwsgi 2.0.22`\n\nSource: https://osv.dev/vulnerability/GHSA-vcph-37mh-fqrh","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}