Vulnerability record · CVE-2019-17567 · published 10 June 2021
CVE-2019-17567: Apache HTTP Server mod_proxy_wstunnel tunnels unvalidated connections
Apache · Http Server
In Apache HTTP Server 2.4.6 through 2.4.46, mod_proxy_wstunnel configured on a URL that the origin server does not actually upgrade to WebSocket still tunnels the entire connection. Subsequent requests on that same connection then pass through without the HTTP validation, authentication, or authorization that would normally apply. This is an HTTP request smuggling class flaw (CWE-444) that can let traffic bypass proxy access controls.
Description
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
high priorityThe flaw enables request smuggling and access-control bypass, and EPSS is very high (about 0.60, 99th percentile), though CVSS is only medium and no KEV listing or known exploitation is recorded.
What it is
In Apache HTTP Server 2.4.6 through 2.4.46, mod_proxy_wstunnel configured on a URL that the origin server does not actually upgrade to WebSocket still tunnels the entire connection. Subsequent requests on that same connection then pass through without the HTTP validation, authentication, or authorization that would normally apply. This is an HTTP request smuggling class flaw (CWE-444) that can let traffic bypass proxy access controls.
Impact
An attacker can smuggle follow-up requests through the tunneled connection and reach backend resources without the validation, authentication, or authorization the proxy would otherwise enforce. The CVSS vector rates only low integrity impact with no confidentiality or availability effect.
Attack surface
Reachable over the network (AV:N) with no privileges and no user interaction (PR:N, UI:N), but only where mod_proxy_wstunnel is configured to proxy a URL that the origin does not upgrade. Exploitation depends on that specific proxy configuration being present.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.60 probability (99th percentile), and references include vendor advisories and a mitigation note but no public exploit tag.
What to do
- Upgrade Apache HTTP Server to a version after 2.4.46 that contains the fix, per the Apache security advisory.
- If immediate upgrade is not possible, apply the mitigation guidance in the oss-security reference and avoid proxying URLs via mod_proxy_wstunnel that the origin does not genuinely upgrade.
- Review mod_proxy_wstunnel proxy configurations and restrict them to endpoints that legitimately perform WebSocket upgrades.
- Apply vendor updates for downstream packages (Fedora, Oracle, Debian, Gentoo, NetApp) that bundle the affected httpd.
- Enforce authentication and authorization at the origin server rather than relying solely on the proxy for tunneled connections.
Detection
- Inspect httpd access and error logs for mod_proxy_wstunnel connections where the origin did not return a 101 Switching Protocols response.
- Look for multiple distinct HTTP requests or unusual request sequences sharing a single proxied connection.
- Monitor for requests reaching backend services through the proxy that bypass expected authentication or authorization checks.
- Alert on proxy configurations that route non-WebSocket URLs through mod_proxy_wstunnel.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-17567 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17567), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.