---
id: CVE-2023-27522
title: 'httpd: mod_proxy_uwsgi HTTP response splitting (CVE-2023-27522)'
summary: >-
  An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server
  via mod_proxy_uwsgi. This security issue occurs when special characters in the
  origin response header can truncate or split the response forwarded to the
  client.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe: CWE-113
vendor: Red Hat
product: Red Hat Enterprise Linux AppStream EUS (v.8.6)
affected:
  - enterprise_linux 6
  - enterprise_linux 7
  - jboss_enterprise_application_platform 6
  - jboss_core_services_on_rhel_7_server
  - jboss_core_services_on_rhel 8
  - enterprise_linux_appstream_eus_v_8_6
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_2
  - enterprise_linux_appstream_v_9
patched:
  - jboss_core_services_on_rhel_7_server
  - jboss_core_services_on_rhel 8
  - enterprise_linux_appstream_eus_v_8_6
  - enterprise_linux_appstream_v_8
  - enterprise_linux_appstream_eus_v_9_2
  - enterprise_linux_appstream_v_9
published: '2023-03-07'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T05:44:31+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-27522'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2176211'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-27522'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27522'
  - url: 'https://httpd.apache.org/security/vulnerabilities_24.html'
  - url: 'https://access.redhat.com/errata/RHSA-2023:4629'
  - url: 'https://access.redhat.com/errata/RHSA-2023:5049'
  - url: 'https://access.redhat.com/errata/RHSA-2023:5050'
  - url: 'https://access.redhat.com/errata/RHSA-2024:4504'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6403'
  - url: >-
      https://github.com/apache/httpd/commit/d753ea76b5972a85349b68c31b59d04c60014f2d
  - url: >-
      https://github.com/unbit/uwsgi/commit/58ee1df31fa9e9af106aaeabb82374c36b433822
  - url: >-
      https://github.com/unbit/uwsgi/commit/acb03530aaaeaa810f28a5b64da619525940f569
  - url: 'https://github.com/unbit/uwsgi'
  - url: 'https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html'
  - url: 'https://security.gentoo.org/glsa/202309-01'
  - url: 'https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.22.html'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.02134
epssPercentile: 0.8122
aliases:
  - GHSA-vcph-37mh-fqrh
  - BIT-apache-2023-27522
  - PYSEC-2026-1058
ecosystem: pip
ingestedAt: '2026-07-08T18:25:53.304Z'
---

## Overview

An HTTP Response Smuggling vulnerability was found in the Apache HTTP Server via mod_proxy_uwsgi. This security issue occurs when special characters in the origin response header can truncate or split the response forwarded to the client.

## Vendor advisories

- **RHSA-2023:4629** · Red Hat · fixed in: Red Hat JBoss Core Services on RHEL 7 Server, Red Hat JBoss Core Services on RHEL 8 · released 2023-08-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:4629)
- **RHSA-2023:5049** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.6) · released 2023-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:5049)
- **RHSA-2023:5050** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2023-09-11 · [advisory](https://access.redhat.com/errata/RHSA-2023:5050)
- **RHSA-2024:4504** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.2) · released 2024-07-11 · [advisory](https://access.redhat.com/errata/RHSA-2024:4504)
- **RHSA-2023:6403** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6403)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Enterprise Application Platform 6 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat JBoss Enterprise Application Platform 6 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-27522.json)

**httpd: mod_proxy_uwsgi HTTP response splitting** — rated Moderate by Red Hat. Released 2023-03-07, updated 2026-09-21.

Affected:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat JBoss Enterprise Application Platform 6

Fixed:

- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- Red Hat Enterprise Linux AppStream EUS (v.8.6)
- Red Hat Enterprise Linux AppStream (v. 8)
- Red Hat Enterprise Linux AppStream EUS (v.9.2)
- Red Hat Enterprise Linux AppStream (v. 9)

No fix planned:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat JBoss Enterprise Application Platform 6

Not affected:

- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Software Collections

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:4629
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, the httpd daemon will be restarted automatically. https://access.redhat.com/errata/RHSA-2023:5049
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

After installing the updated packages, the httpd daemon will be restarted automatically. https://access.redhat.com/errata/RHSA-2023:5050

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2023-27522)

Affected packages:

- `uwsgi < 2.0.22`

Patched in:

- `uwsgi 2.0.22`

Source: https://osv.dev/vulnerability/GHSA-vcph-37mh-fqrh
