Vulnerability record · CVE-2012-0053 · published 28 January 2012
CVE-2012-0053: Apache HTTP Server 400 error page leaks HTTPOnly cookies
Apache · Http Server
Apache HTTP Server 2.2.x through 2.2.21 fails to restrict header information when building Bad Request (400) error documents. A long or malformed header combined with a crafted web script causes the server to echo HTTPOnly cookie values into the error response. This defeats the HTTPOnly protection meant to keep session cookies out of reach of scripts.
Description
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
AV:N/AC:M/Au:N/C:P/I:N/A:N
Automated analysis
high priorityAlthough CVSS 2.0 is only 4.3 (MEDIUM), the EPSS score is 0.82198 at the 99.6th percentile and the flaw directly exposes HTTPOnly session cookies, making real-world exploitation likely and impactful.
What it is
Apache HTTP Server 2.2.x through 2.2.21 fails to restrict header information when building Bad Request (400) error documents. A long or malformed header combined with a crafted web script causes the server to echo HTTPOnly cookie values into the error response. This defeats the HTTPOnly protection meant to keep session cookies out of reach of scripts.
Impact
An attacker can read HTTPOnly cookie values, including session identifiers, enabling session hijacking or account takeover. The leak is limited to confidentiality; no integrity or availability impact is described.
Attack surface
Reachable remotely over the network (AV:N) with no authentication (Au:N), but requires a crafted web script and a long or malformed header, giving medium attack complexity (AC:M). No user interaction is required by the vector.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high (0.82198, 99.6th percentile), indicating strong predicted exploitation activity. References include a vendor patch and multiple third-party advisories.
What to do
- Upgrade Apache HTTP Server to a version after 2.2.21 that includes the fix (see Apache 2.2 vulnerabilities page and revision 1235454).
- Apply vendor errata for affected distributions (Red Hat RHSA-2012-0128/0542/0543, Debian DSA-2405, openSUSE advisories).
- If immediate upgrade is not possible, review exposure of HTTPOnly session cookies and consider shortening session lifetimes or rotating session identifiers.
- Monitor for 400 responses containing cookie values and treat such responses as a sign of attempted exploitation.
Detection
- Search web server logs for 400 Bad Request responses with unusually long or malformed headers.
- Inspect 400 error response bodies for echoed Cookie or Set-Cookie values.
- Alert on requests combining crafted script parameters with oversized or malformed headers.
- Correlate 400 error spikes with subsequent session reuse from different client addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0053 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0053), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.