← Vulnerability feed

Vulnerability record · CVE-2016-5388 · published 19 July 2016

CVE-2016-5388: Apache Tomcat CGI Servlet HTTP_PROXY header injection (httpoxy)

Redhat · Enterprise Linux Desktop

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, passes the client-supplied Proxy header into the HTTP_PROXY environment variable as required by RFC 3875 section 4.1.18. This lets a remote attacker control the proxy setting used by CGI applications, redirecting their outbound HTTP traffic. The record notes the vendor treats this as a planned mitigation rather than a standalone vulnerability.

8.1 CVSS 3.0 High EPSS 51% · top 1.1% CWE-284 · Improper access control
8.1CVSS 3.0 base score, v2 5.1
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
50References
17 Jun 2026Last modified by NVD

Description

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.1 with high EPSS and no authentication or user interaction required, though exploitation depends on the CGI Servlet being enabled and the application making outbound HTTP calls.

What it is

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, passes the client-supplied Proxy header into the HTTP_PROXY environment variable as required by RFC 3875 section 4.1.18. This lets a remote attacker control the proxy setting used by CGI applications, redirecting their outbound HTTP traffic. The record notes the vendor treats this as a planned mitigation rather than a standalone vulnerability.

Impact

An attacker can redirect outbound HTTP requests made by CGI applications to an arbitrary proxy server they control, enabling interception or manipulation of that traffic. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable remotely over the network via a crafted Proxy header in an HTTP request; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). It only applies where the CGI Servlet is enabled and the CGI application makes outbound HTTP calls.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.50896 probability, 98.873 percentile), and references are advisory, patch and vendor-response pages rather than exploit code.

What to do

  • Upgrade Tomcat to a release containing the vendor's planned httpoxy mitigation, or apply the relevant Red Hat, Oracle or HPE errata for bundled Tomcat.
  • If the CGI Servlet is not needed, disable it (remove or comment the CGI servlet and its servlet-mapping in web.xml).
  • Where CGI must remain, strip or reject client-supplied Proxy headers at the reverse proxy or web server before they reach Tomcat.
  • Set HTTP_PROXY explicitly in the CGI execution environment so client input cannot override it.
  • Review CGI applications that make outbound HTTP calls and route them through a trusted, explicitly configured proxy.

Detection

  • Inspect HTTP request logs for client-supplied Proxy headers reaching Tomcat, especially on paths served by the CGI Servlet.
  • Monitor CGI application outbound connections for traffic to unexpected or attacker-controlled proxy destinations.
  • Audit Tomcat web.xml and server configuration for enabled CGI Servlet deployments.
  • Correlate outbound proxy anomalies with requests containing Proxy headers to identify attempted redirection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1624.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2045.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2046.html Third Party Advisory
http://www.kb.cert.org/vuls/id/797896 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html Third Party Advisory
http://www.securityfocus.com/bid/91818 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036331 Third Party AdvisoryVDB EntryVendor Advisory
https://access.redhat.com/errata/RHSA-2016:1635 Third Party Advisory
https://access.redhat.com/errata/RHSA-2016:1636 Third Party Advisory
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory
https://httpoxy.org/ Third Party Advisory
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apach
https://lists.apache.org/thread.html/6b414817c2b0bf351138911c8c922ec5dd577ebc0b9a7f42d705752d%40%3Cissues.activemq.apach
https://lists.apache.org/thread.html/6d3d34adcf3dfc48e36342aa1f18ce3c20bb8e4c458a97508d5bfed1%40%3Cissues.activemq.apach
https://lists.apache.org/thread.html/r2853582063cfd9e7fbae1e029ae004e6a83482ae9b70a698996353dd%40%3Cusers.tomcat.apache.
https://lists.apache.org/thread.html/rc6b2147532416cc736e68a32678d3947b7053c3085cf43a9874fd102%40%3Cusers.tomcat.apache.
https://lists.apache.org/thread.html/rf21b368769ae70de4dee840a3228721ae442f1d51ad8742003aefe39%40%3Cusers.tomcat.apache.
https://lists.debian.org/debian-lts-announce/2019/08/msg00015.html
https://tomcat.apache.org/tomcat-7.0-doc/changelog.html Release NotesVendor Advisory
https://www.apache.org/security/asf-httpoxy-response.txt Vendor Advisory
http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-1624.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2045.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2046.html Third Party Advisory
http://www.kb.cert.org/vuls/id/797896 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html Third Party Advisory
http://www.securityfocus.com/bid/91818 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036331 Third Party AdvisoryVDB EntryVendor Advisory
https://access.redhat.com/errata/RHSA-2016:1635 Third Party Advisory
https://access.redhat.com/errata/RHSA-2016:1636 Third Party Advisory
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722 Third Party Advisory

Track CVE-2016-5388 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2016-5388), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.