Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apache HTTP Server can be tricked into sending malformed requests to backend servers when using certain rewrite or proxy rules. An attacker can exploit this to bypass security controls, access unintended content, or poison caches.
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.0–2.4.55 occurring when mod_proxy is combined with mod_rewrite rules that match and reinject unsanitized user-supplied URL data into proxied requests. Attack vector requires attacker-controlled request-target input; exploitation can result in access control bypass, URL smuggling to origin servers, and cache poisoning.