CVE-2023-38709
Advisory lineage Upstream: 0 Downstream: 17
Modified
Published: 04 Apr 2024, 19:19
Last modified:04 Nov 2025, 21:08
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.3 HIGH
v3.1 (cve.org)
EPSS Score
4.36% LOW
4% probability +1.10%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Apr 2024, 19:19
Published
Vulnerability first disclosed
04 Nov 2025, 21:08
Last Modified
Vulnerability information updated
Description
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
CVSS Metrics
- v3.1•HIGH•Score: 7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Trends
Current EPSS score: 4.36%• Percentile: 89%
Techniques & Countermeasures
- CWE-1284•Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Affected Systems
- apache software foundation•apache http server
≤ 2.4.58
- Unknown•HTTP Server
< 2.4.59
- Unknown•macOS
< 14.6
- broadcom•fabric_operating_system
na
- debian•debian_linux
10.0
- fedoraproject•fedora
38 | 39 | 40
- netapp•ontap
9
- netapp•ontap_tools
10
References (11)
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security.netapp.com/advisory/ntap-20240415-0013/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/
- http://www.openwall.com/lists/oss-security/2024/04/04/3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/
- https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
- https://support.apple.com/kb/HT214119
- http://seclists.org/fulldisclosure/2024/Jul/18
- http://www.openwall.com/lists/oss-security/2025/07/10/2
- http://www.openwall.com/lists/oss-security/2025/07/10/3