Vulnerability record · CVE-2015-3183 · published 20 July 2015
CVE-2015-3183: Apache HTTP Server chunked transfer coding request smuggling
Apache · Http Server
The chunked transfer coding parser in Apache HTTP Server before 2.4.14 mishandles large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c, so it does not properly parse chunk headers. This lets remote attackers craft requests that are interpreted differently by front-end and back-end HTTP components, enabling HTTP request smuggling. Because smuggling can bypass access controls and poison caches, it matters to any deployment where httpd sits behind or in front of another HTTP parser.
Description
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw enables request smuggling with no authentication required, and although CVSS 2.0 rates it medium, the very high EPSS score and broad multi-vendor patch activity indicate real exploitation pressure.
What it is
The chunked transfer coding parser in Apache HTTP Server before 2.4.14 mishandles large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c, so it does not properly parse chunk headers. This lets remote attackers craft requests that are interpreted differently by front-end and back-end HTTP components, enabling HTTP request smuggling. Because smuggling can bypass access controls and poison caches, it matters to any deployment where httpd sits behind or in front of another HTTP parser.
Impact
An attacker can smuggle a second request past front-end controls, potentially reaching endpoints or resources that should be blocked and poisoning shared caches for other users. The CVSS 2.0 vector shows integrity impact only (I:P), with no confidentiality or availability impact recorded.
Attack surface
Reachable over the network via a crafted HTTP request to the affected server; the vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Exploitation depends on the request passing through a chain of HTTP parsers that disagree on chunk framing.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.73327 (99.4th percentile), indicating elevated predicted exploitation activity. References are vendor advisories, distribution errata and patch notices; none are tagged as exploit code, so public exploit availability is not confirmed by this record.
What to do
- Upgrade Apache HTTP Server to 2.4.14 or later, or apply the vendor/distribution backport for your platform.
- Apply the referenced Red Hat, Debian, Ubuntu, SUSE and Oracle errata where the base httpd package cannot be upgraded directly.
- Normalize HTTP parsing across the request chain so front-end proxies and back-end servers use the same chunked-encoding rules and reject ambiguous framing.
- Reject or drop requests with malformed chunk headers, oversized chunk-size values or invalid chunk-extension characters at the edge.
- Review cache and access-control configuration for exposure if smuggling is suspected, and invalidate cached responses where feasible.
Detection
- Inspect HTTP logs and proxy logs for requests containing malformed chunk headers, unusually large chunk-size values or invalid chunk-extension characters.
- Correlate front-end and back-end request logs for discrepancies in request counts, paths or methods that suggest smuggled requests.
- Monitor for repeated or duplicated requests to the same endpoint from a single source that bypass expected access-control decisions.
- Alert on cache entries or responses that do not match the originating client request, which can indicate cache poisoning via smuggling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3183 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3183), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.