VYPR
Unrated severityNVD Advisory· Published Jul 10, 2025· Updated Nov 4, 2025

Apache HTTP Server: HTTP response splitting

CVE-2024-42516

Description

HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response.

This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue.

Users are recommended to upgrade to version 2.4.64, which fixes this issue.

Affected products

2
  • Range: >= 2.4.59, < 2.4.64
  • Apache Software Foundation/Apache HTTP Serverv5
    Range: 2.4.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.