CVE detail
CVE-2026-33523
HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- Debian 13.5 point release lands with security fixes, bug patchesHelp Net Security
Debian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Fresh installer images carrying the same fixes will follow at the regular download locations. Sysadmins running trixie do not need to reinstall. Existing media remain valid, and machines … More →
newswww.helpnetsecurity.comMay 17, 2026, 10:03 PM - CVE-2026-33523 Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status lineMicrosoft MSRC
Information published.
vendormsrc.microsoft.comMay 7, 2026, 8:11 AM The most severe of these security defects could allow remote attackers to execute arbitrary code.
newswww.securityweek.comMay 5, 2026, 11:19 AM- http://www.openwall.com/lists/oss-security/2026/05/04/23www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 4, 2026, 3:16 PM - https://httpd.apache.org/security/vulnerabilities_24.htmlhttpd.apache.org
No excerpt available.
Vendor Advisoryhttpd.apache.orgMay 4, 2026, 3:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-49975CVSS 7.5 · High
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP…
- CVE-2026-48913CVSS 7.3 · High
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
- CVE-2026-44631CVSS 9.8 · Critical
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. User…
- CVE-2026-44186CVSS 7.3 · High
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue…
- CVE-2026-44185CVSS 7.3 · High
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.…
- CVE-2026-44119CVSS 5.5 · Medium
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issu…