← Vulnerability feed

Vulnerability record · CVE-2006-3918 · published 28 July 2006

CVE-2006-3918: Apache and IBM HTTP Server Expect header XSS in error messages

Apache · Http Server

Apache HTTP Server and IBM HTTP Server fail to sanitize the Expect request header before reflecting it in error messages. This allows cross-site scripting style attacks when a client component, such as a Flash SWF file, can send arbitrary headers. The flaw affects multiple older server branches and was patched by the vendors.

4.3 CVSS 2.0 Medium EPSS 95% · top 0.1% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
112References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS 2.0 scores this as medium with partial integrity impact, but the very high EPSS and public exploit references raise concern for exposed legacy servers.

What it is

Apache HTTP Server and IBM HTTP Server fail to sanitize the Expect request header before reflecting it in error messages. This allows cross-site scripting style attacks when a client component, such as a Flash SWF file, can send arbitrary headers. The flaw affects multiple older server branches and was patched by the vendors.

Impact

An attacker can inject script content into a server error response, potentially executing code in the context of a victim's browser session. The CVSS vector shows partial integrity impact with no confidentiality or availability impact.

Attack surface

The flaw is reachable over the network via HTTP requests containing a crafted Expect header. No authentication is required, but exploitation depends on a client component capable of sending arbitrary headers, as demonstrated with a Flash SWF file.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.95103 (99.86th percentile). Two Bugtraq references are tagged as Exploit, indicating public exploit material exists.

What to do

  • Upgrade Apache HTTP Server to 1.3.35, 2.0.58, or 2.2.2 or later, and IBM HTTP Server to 6.0.2.13 or 6.1.0.1 or later.
  • Apply vendor errata such as RHSA-2006-0618 and RHSA-2006-0692 for Red Hat Enterprise Linux.
  • Sanitize or encode the Expect header before reflecting it in any error response.
  • Restrict or disable client components such as Flash that can send arbitrary HTTP headers if not required.
  • Review reverse proxy and load balancer configurations for header reflection behavior.

Detection

  • Search web server error logs for requests containing unusual or script-like Expect header values.
  • Monitor for HTTP responses that reflect Expect header content in error pages.
  • Use network detection to flag Flash or other client components sending custom Expect headers to web servers.
  • Audit web server versions against the fixed releases listed in vendor advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20060801-01-P Broken Link
http://archives.neohapsis.com/archives/bugtraq/2006-05/0151.html Broken LinkExploit
http://archives.neohapsis.com/archives/bugtraq/2006-07/0425.html Broken LinkExploit
http://kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html Mailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=125631037611762&w=2 Issue TrackingMailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=129190899612998&w=2 Issue TrackingMailing ListThird Party Advisory
http://marc.info/?l=bugtraq&m=130497311408250&w=2 Issue TrackingMailing ListThird Party Advisory
http://openbsd.org/errata.html#httpd2 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2006-0618.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2006-0692.html Third Party Advisory
http://secunia.com/advisories/21172 Not ApplicablePatchVendor Advisory
http://secunia.com/advisories/21174 Not ApplicablePatchVendor Advisory
http://secunia.com/advisories/21399 Not Applicable
http://secunia.com/advisories/21478 Not Applicable
http://secunia.com/advisories/21598 Not Applicable
http://secunia.com/advisories/21744 Not Applicable
http://secunia.com/advisories/21848 Not Applicable
http://secunia.com/advisories/21986 Not Applicable
http://secunia.com/advisories/22140 Not Applicable
http://secunia.com/advisories/22317 Not Applicable
http://secunia.com/advisories/22523 Not Applicable
http://secunia.com/advisories/28749 Not Applicable
http://secunia.com/advisories/29640 Not Applicable
http://secunia.com/advisories/40256 Not Applicable
http://securityreason.com/securityalert/1294 ExploitThird Party Advisory
http://securitytracker.com/id?1016569 Broken LinkThird Party AdvisoryVDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2006-194.htm Third Party Advisory
http://svn.apache.org/viewvc?view=rev&revision=394965 ExploitVendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1PK24631 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg24013080 Third Party Advisory
http://www.debian.org/security/2006/dsa-1167 Third Party Advisory
http://www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-2.html Third Party Advisory
http://www.novell.com/linux/security/advisories/2006_51_apache.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2006-0619.html Third Party Advisory
http://www.securityfocus.com/bid/19661 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1024144 Broken LinkThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/usn-575-1 Third Party Advisory
http://www.vupen.com/english/advisories/2006/2963 Permissions Required
http://www.vupen.com/english/advisories/2006/2964 Permissions Required

Track CVE-2006-3918 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2006-3918), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.