Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache HTTP Server: request smuggling

High7.5CVE-2026-63718 · Published Oct 1, 2026 · updated Oct 6, 2026

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.

Affected versions

PackageAffectedFixed in
Apache HTTP Server
Product
>= 2.4.30, <= 2.4.68No fix yet
Details and references

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1
Apache HTTP Server: out-of-bounds write
High7.5Oct 1