CVE-2026-33523Patch(apache / http_server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apache http_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-443

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
http_server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-11: 3Patch / Workaround · 2026-05-11: 305-11
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1 https://kusanagi.tokyo/releases/24495/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, CVE-2026-...

    Post summary

    Kusanagi’s module update to httpd24 2.4.67‑1 patches multiple CVE‑identified vulnerabilities, without mentioning exploits or ongoing attacks.

    0101066
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 モジュール更新情報 2.4.67-1.el9 https://kusanagi.tokyo/releases/24489/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 httpd24 2.4.67-1.el9 この更新には脆弱性(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523, CVE-2026-33007, CVE-2026-33006, C...

    Post summary

    The release notes announce a kusanagi-httpd24 module update (to 2.4.67-1.el9) that patches several CVEs, indicating a focus on patching rather than exploitation or PoC discussion.

    0101062
    200 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-httpd24 Module Update 2.4.67-1 https://kusanagi.tokyo/en/releases/24496/ KUSANAGI 9 modules have been updated. The updated modules are as follows: httpd24 2.4.67-1 This update includes support for vulnerability(CVE-2026-34059, CVE-2026-34032, CVE-2026-33857, CVE-2026-33523,...

    Post summary

    The text announces a module update that patches multiple CVEs, providing a workaround via the updated version.

    0000042
    200 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---

Explore more