← Vulnerability feed

Vulnerability record · CVE-2019-17567 · published 10 June 2021

CVE-2019-17567: Apache HTTP Server mod_proxy_wstunnel tunnels unvalidated connections

Apache · Http Server

In Apache HTTP Server 2.4.6 through 2.4.46, mod_proxy_wstunnel configured on a URL that the origin server does not actually upgrade to WebSocket still tunnels the entire connection. Subsequent requests on that same connection then pass through without the HTTP validation, authentication, or authorization that would normally apply. This is an HTTP request smuggling class flaw (CWE-444) that can let traffic bypass proxy access controls.

5.3 CVSS 3.1 Medium EPSS 60% · top 0.9% CWE-444 · HTTP request smuggling
5.3CVSS 3.1 base score, v2 5.0
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw enables request smuggling and access-control bypass, and EPSS is very high (about 0.60, 99th percentile), though CVSS is only medium and no KEV listing or known exploitation is recorded.

What it is

In Apache HTTP Server 2.4.6 through 2.4.46, mod_proxy_wstunnel configured on a URL that the origin server does not actually upgrade to WebSocket still tunnels the entire connection. Subsequent requests on that same connection then pass through without the HTTP validation, authentication, or authorization that would normally apply. This is an HTTP request smuggling class flaw (CWE-444) that can let traffic bypass proxy access controls.

Impact

An attacker can smuggle follow-up requests through the tunneled connection and reach backend resources without the validation, authentication, or authorization the proxy would otherwise enforce. The CVSS vector rates only low integrity impact with no confidentiality or availability effect.

Attack surface

Reachable over the network (AV:N) with no privileges and no user interaction (PR:N, UI:N), but only where mod_proxy_wstunnel is configured to proxy a URL that the origin does not upgrade. Exploitation depends on that specific proxy configuration being present.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.60 probability (99th percentile), and references include vendor advisories and a mitigation note but no public exploit tag.

What to do

  • Upgrade Apache HTTP Server to a version after 2.4.46 that contains the fix, per the Apache security advisory.
  • If immediate upgrade is not possible, apply the mitigation guidance in the oss-security reference and avoid proxying URLs via mod_proxy_wstunnel that the origin does not genuinely upgrade.
  • Review mod_proxy_wstunnel proxy configurations and restrict them to endpoints that legitimately perform WebSocket upgrades.
  • Apply vendor updates for downstream packages (Fedora, Oracle, Debian, Gentoo, NetApp) that bundle the affected httpd.
  • Enforce authentication and authorization at the origin server rather than relying solely on the proxy for tunneled connections.

Detection

  • Inspect httpd access and error logs for mod_proxy_wstunnel connections where the origin did not return a 101 Switching Protocols response.
  • Look for multiple distinct HTTP requests or unusual request sequences sharing a single proxied connection.
  • Monitor for requests reaching backend services through the proxy that bypass expected authentication or authorization checks.
  • Alert on proxy configurations that route non-WebSocket URLs through mod_proxy_wstunnel.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://httpd.apache.org/security/vulnerabilities_24.html Release NotesVendor Advisory
http://www.openwall.com/lists/oss-security/2021/06/10/2 Mailing ListMitigationThird Party Advisory
https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org
https://lists.apache.org/thread.html/r90f693a5c9fb75550ef1412436d5e682a5f845beb427fa6f23419a3c%40%3Cannounce.httpd.apach
https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org Mailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7T
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3H
https://security.gentoo.org/glsa/202107-38 Third Party Advisory
https://security.netapp.com/advisory/ntap-20210702-0001/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory
http://httpd.apache.org/security/vulnerabilities_24.html Release NotesVendor Advisory
http://www.openwall.com/lists/oss-security/2021/06/10/2 Mailing ListMitigationThird Party Advisory
https://lists.apache.org/thread.html/r7f2b70b621651548f4b6f027552f1dd91705d7111bb5d15cda0a68dd%40%3Cdev.httpd.apache.org
https://lists.apache.org/thread.html/r90f693a5c9fb75550ef1412436d5e682a5f845beb427fa6f23419a3c%40%3Cannounce.httpd.apach
https://lists.apache.org/thread.html/re026d3da9d7824bd93b9f871c0fdda978d960c7e62d8c43cba8d0bf3%40%3Ccvs.httpd.apache.org Mailing ListVendor Advisory
https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7T
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3H
https://security.gentoo.org/glsa/202107-38 Third Party Advisory
https://security.netapp.com/advisory/ntap-20210702-0001/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory

Track CVE-2019-17567 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-17567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.