CVE-2016-8743

7.5 HIGH
Published: July 27, 2017 Modified: May 13, 2026
View on NVD

Description

Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-1415.html
Source: security@apache.org
Third Party Advisory
http://www.debian.org/security/2017/dsa-3796
Source: security@apache.org
Third Party Advisory
http://www.securityfocus.com/bid/95077
Source: security@apache.org
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037508
Source: security@apache.org
Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:0906
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1161
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1413
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1414
Source: security@apache.org
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1721
Source: security@apache.org
Third Party Advisory
https://security.gentoo.org/glsa/201701-36
Source: security@apache.org
Patch Third Party Advisory VDB Entry
https://security.netapp.com/advisory/ntap-20180423-0001/
Source: security@apache.org
Third Party Advisory
https://support.apple.com/HT208221
Source: security@apache.org
Third Party Advisory
https://www.tenable.com/security/tns-2017-04
Source: security@apache.org
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-1415.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2017/dsa-3796
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.securityfocus.com/bid/95077
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037508
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
https://access.redhat.com/errata/RHSA-2017:0906
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1161
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1413
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1414
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:1721
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-8743
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://security.gentoo.org/glsa/201701-36
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory VDB Entry
https://security.netapp.com/advisory/ntap-20180423-0001/
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://support.apple.com/HT208221
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.tenable.com/security/tns-2017-04
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

80 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
13.3%
96th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

netapp apache debian redhat