[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-25690":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":28,"duplicate_of":9,"upstream":29,"downstream":30,"duplicates":79,"related":80,"reserved_at":9,"published_at":88,"modified_at":89,"state":90,"summary":91,"references_raw":99,"kevs":118,"epss":119,"epss_history":122,"metrics":351,"affected":358},"CVE-2023-25690","Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.\n\n\n\n\nConfigurations are affected when mod_proxy is enabled along with some form of RewriteRule\n or ProxyPassMatch in which a non-specific pattern matches\n some portion of the user-supplied request-target (URL) data and is then\n re-inserted into the proxied request-target using variable \nsubstitution. For example, something like:\n\n\n\n\nRewriteEngine on\nRewriteRule \"^/here/(.*)\" \"http://example.com:8080/elsewhere?$1\"; [P]\nProxyPassReverse /here/ http://example.com:8080/\n\n\nRequest splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-444","Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","The product acts as an intermediary HTTP agent\n         (such as a proxy or firewall) in the data flow between two\n         entities such as a client and server, but it does not\n         interpret malformed HTTP requests or responses in ways that\n         are consistent with how the messages will be processed by\n         those entities that are at the ultimate destination.","weakness","Incomplete","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-273","HTTP Response Smuggling",[],{"id":24,"name":25,"techniques":26},"CAPEC-33","HTTP Request Smuggling",[],[],[],[],[31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75,77],{"_key":32},"ALPINE-CVE-2023-25690",{"_key":34},"SUSE-SU-2023:0764-1",{"_key":36},"SUSE-SU-2023:0799-1",{"_key":38},"SUSE-SU-2023:0803-1",{"_key":40},"SUSE-SU-2023:1573-1",{"_key":42},"SUSE-SU-2023:1658-1",{"_key":44},"OPENSUSE-SU-2024:12776-1",{"_key":46},"DLA-3401-1",{"_key":48},"DSA-5376-1",{"_key":50},"RHSA-2023:1547",{"_key":52},"RHSA-2023:1593",{"_key":54},"RHSA-2023:1596",{"_key":56},"RHSA-2023:1597",{"_key":58},"RHSA-2023:1670",{"_key":60},"RHSA-2023:1672",{"_key":62},"RHSA-2023:1673",{"_key":64},"RHSA-2023:1916",{"_key":66},"RHSA-2023:3292",{"_key":68},"RHSA-2023:3354",{"_key":70},"MGASA-2023-0100",{"_key":72},"USN-5942-1",{"_key":74},"DEBIAN-CVE-2023-25690",{"_key":76},"USN-5942-2",{"_key":78},"UBUNTU-CVE-2023-25690",[],[81,82,83,84,85,86,87],{"_key":34},{"_key":36},{"_key":38},{"_key":40},{"_key":42},{"_key":44},{"_key":70},"2023-03-07T15:09:03.080Z","2025-12-18T15:37:41.866Z","Modified",{"cisa_kev":92,"cisa_ransomware":92,"cisa_vendor":9,"epss_severity":93,"epss_score":94,"severity":93,"severity_score":95,"severity_version":96,"severity_source":97,"severity_vector":98,"severity_status":90},false,"critical",0.67011,9.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[100,106,110,114],{"url":101,"sources":102,"tags":104},"https://httpd.apache.org/security/vulnerabilities_24.html",[97,103],"nvd",[105],"Vendor Advisory",{"url":107,"sources":108,"tags":109},"https://lists.debian.org/debian-lts-announce/2023/04/msg00028.html",[97,103],[],{"url":111,"sources":112,"tags":113},"https://security.gentoo.org/glsa/202309-01",[97,103],[],{"url":115,"sources":116,"tags":117},"http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.html",[97,103],[],[],{"date":120,"score":94,"percentile":121},"2026-06-04",0.9857,[123,127,130,132,135,137,139,141,143,146,149,152,154,156,158,162,164,166,168,171,174,176,178,180,182,185,187,189,193,196,198,200,202,204,206,208,210,212,214,217,219,221,223,226,229,233,235,237,240,243,245,248,251,254,258,260,263,265,268,272,274,276,279,282,284,287,289,292,295,297,299,301,304,306,309,312,315,318,320,322,325,328,331,333,336,339,342,344,346,348],{"date":124,"score":125,"percentile":126},"2025-11-04",0.67037,0.98475,{"date":128,"score":125,"percentile":129},"2025-11-05",0.98474,{"date":131,"score":125,"percentile":129},"2025-11-06",{"date":133,"score":125,"percentile":134},"2025-11-07",0.98473,{"date":136,"score":125,"percentile":129},"2025-11-08",{"date":138,"score":125,"percentile":134},"2025-11-09",{"date":140,"score":125,"percentile":129},"2025-11-10",{"date":142,"score":125,"percentile":134},"2025-11-11",{"date":144,"score":125,"percentile":145},"2025-11-12",0.98476,{"date":147,"score":125,"percentile":148},"2025-11-13",0.98478,{"date":150,"score":125,"percentile":151},"2025-11-14",0.98477,{"date":153,"score":125,"percentile":145},"2025-11-15",{"date":155,"score":125,"percentile":151},"2025-11-16",{"date":157,"score":125,"percentile":151},"2025-11-17",{"date":159,"score":160,"percentile":161},"2025-11-18",0.89156,0.99625,{"date":163,"score":160,"percentile":161},"2025-11-19",{"date":165,"score":160,"percentile":161},"2025-11-20",{"date":167,"score":125,"percentile":134},"2025-11-21",{"date":169,"score":125,"percentile":170},"2025-11-22",0.98472,{"date":172,"score":125,"percentile":173},"2025-11-23",0.9847,{"date":175,"score":125,"percentile":173},"2025-11-24",{"date":177,"score":125,"percentile":170},"2025-11-25",{"date":179,"score":125,"percentile":170},"2025-11-26",{"date":181,"score":125,"percentile":134},"2025-11-27",{"date":183,"score":125,"percentile":184},"2025-11-28",0.98471,{"date":186,"score":125,"percentile":170},"2025-11-29",{"date":188,"score":125,"percentile":184},"2025-11-30",{"date":190,"score":191,"percentile":192},"2025-12-01",0.56875,0.98027,{"date":194,"score":191,"percentile":195},"2025-12-02",0.98028,{"date":197,"score":191,"percentile":192},"2025-12-03",{"date":199,"score":125,"percentile":170},"2025-12-04",{"date":201,"score":125,"percentile":134},"2025-12-05",{"date":203,"score":125,"percentile":134},"2025-12-06",{"date":205,"score":125,"percentile":129},"2025-12-07",{"date":207,"score":125,"percentile":129},"2025-12-08",{"date":209,"score":125,"percentile":126},"2025-12-09",{"date":211,"score":125,"percentile":151},"2025-12-10",{"date":213,"score":125,"percentile":148},"2025-12-11",{"date":215,"score":125,"percentile":216},"2025-12-12",0.9848,{"date":218,"score":125,"percentile":216},"2025-12-13",{"date":220,"score":125,"percentile":216},"2025-12-14",{"date":222,"score":125,"percentile":216},"2025-12-15",{"date":224,"score":125,"percentile":225},"2025-12-16",0.98481,{"date":227,"score":125,"percentile":228},"2025-12-17",0.98482,{"date":230,"score":231,"percentile":232},"2025-12-18",0.68197,0.98526,{"date":234,"score":231,"percentile":232},"2025-12-19",{"date":236,"score":231,"percentile":232},"2025-12-20",{"date":238,"score":231,"percentile":239},"2025-12-21",0.98527,{"date":241,"score":231,"percentile":242},"2025-12-22",0.98528,{"date":244,"score":231,"percentile":242},"2025-12-23",{"date":246,"score":231,"percentile":247},"2025-12-24",0.98529,{"date":249,"score":231,"percentile":250},"2025-12-25",0.98531,{"date":252,"score":231,"percentile":253},"2025-12-26",0.9853,{"date":255,"score":256,"percentile":257},"2025-12-27",0.67563,0.98523,{"date":259,"score":231,"percentile":250},"2025-12-28",{"date":261,"score":231,"percentile":262},"2025-12-29",0.98532,{"date":264,"score":231,"percentile":262},"2025-12-30",{"date":266,"score":125,"percentile":267},"2025-12-31",0.98488,{"date":269,"score":270,"percentile":271},"2026-01-01",0.58163,0.98111,{"date":273,"score":270,"percentile":271},"2026-01-02",{"date":275,"score":270,"percentile":271},"2026-01-03",{"date":277,"score":125,"percentile":278},"2026-01-04",0.98489,{"date":280,"score":125,"percentile":281},"2026-01-05",0.9849,{"date":283,"score":125,"percentile":281},"2026-01-06",{"date":285,"score":125,"percentile":286},"2026-01-07",0.98491,{"date":288,"score":125,"percentile":286},"2026-01-08",{"date":290,"score":125,"percentile":291},"2026-01-09",0.98493,{"date":293,"score":125,"percentile":294},"2026-01-10",0.98494,{"date":296,"score":125,"percentile":294},"2026-01-11",{"date":298,"score":125,"percentile":294},"2026-01-12",{"date":300,"score":125,"percentile":291},"2026-01-13",{"date":302,"score":125,"percentile":303},"2026-01-14",0.98495,{"date":305,"score":125,"percentile":303},"2026-01-15",{"date":307,"score":125,"percentile":308},"2026-01-16",0.98496,{"date":310,"score":125,"percentile":311},"2026-01-17",0.98498,{"date":313,"score":125,"percentile":314},"2026-01-18",0.98499,{"date":316,"score":125,"percentile":317},"2026-01-19",0.98501,{"date":319,"score":125,"percentile":317},"2026-01-20",{"date":321,"score":125,"percentile":317},"2026-01-21",{"date":323,"score":125,"percentile":324},"2026-01-22",0.98502,{"date":326,"score":125,"percentile":327},"2026-01-23",0.98504,{"date":329,"score":125,"percentile":330},"2026-01-24",0.98505,{"date":332,"score":125,"percentile":327},"2026-01-25",{"date":334,"score":125,"percentile":335},"2026-01-26",0.98506,{"date":337,"score":125,"percentile":338},"2026-01-27",0.98507,{"date":340,"score":125,"percentile":341},"2026-01-28",0.98508,{"date":343,"score":125,"percentile":341},"2026-01-29",{"date":345,"score":125,"percentile":341},"2026-01-30",{"date":347,"score":125,"percentile":338},"2026-01-31",{"date":349,"score":270,"percentile":350},"2026-02-01",0.98136,[352,356],{"source":97,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":353,"cvss_v4_0":9},{"baseScore":95,"baseSeverity":354,"vectorString":98,"impactScore":95,"exploitabilityScore":355},"CRITICAL",10,{"source":103,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":357,"cvss_v4_0":9},{"baseScore":95,"baseSeverity":354,"vectorString":98,"impactScore":95,"exploitabilityScore":355},[359,371],{"ecosystem":9,"name":360,"vendor":361,"product":362,"cpe_part":363,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":364},"Apache HTTP Server","apache software foundation","apache http server","a",[365],{"version":366,"is_range":367,"range_type":97,"version_start":368,"version_start_type":369,"version_end":370,"version_end_type":369,"fixed_in":9},">= 2.4.0, \u003C= 2.4.55",true,"2.4.0","including","2.4.55",{"ecosystem":9,"name":372,"vendor":9,"product":372,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":373},"HTTP Server",[374],{"version":375,"is_range":367,"range_type":376,"version_start":368,"version_start_type":369,"version_end":370,"version_end_type":369,"fixed_in":9},"gte2.4.0_lte2.4.55","cpe"]