Vulnerability record · CVE-2023-25690 · published 7 March 2023
CVE-2023-25690: Apache HTTP Server mod_proxy request smuggling via RewriteRule substitution
Apache · Http Server
Apache HTTP Server 2.4.0 through 2.4.55 with mod_proxy enabled and certain RewriteRule or ProxyPassMatch configurations can be tricked into re-inserting user-controlled request-target data into a proxied request, enabling HTTP request smuggling. This matters because smuggling can bypass proxy access controls, route unintended URLs to origin servers, and poison caches.
Description
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and a very high EPSS score make this a top remediation priority despite no KEV listing.
What it is
Apache HTTP Server 2.4.0 through 2.4.55 with mod_proxy enabled and certain RewriteRule or ProxyPassMatch configurations can be tricked into re-inserting user-controlled request-target data into a proxied request, enabling HTTP request smuggling. This matters because smuggling can bypass proxy access controls, route unintended URLs to origin servers, and poison caches.
Impact
An unauthenticated attacker can smuggle a second request through the proxy, bypassing access controls and reaching backend origin servers with attacker-chosen URLs. This can also poison shared caches, affecting other users.
Attack surface
Reachable over the network via crafted HTTP requests to a vulnerable proxy configuration; no authentication or user interaction is required per the CVSS vector. Only deployments using mod_proxy with the described RewriteRule or ProxyPassMatch variable-substitution patterns are affected.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.845 (99.7th percentile), indicating strong likelihood of exploitation activity. A public Packet Storm advisory exists, though no exploit tag is attached.
What to do
- Upgrade Apache HTTP Server to at least 2.4.56, which is the vendor-recommended fix.
- Audit mod_proxy configurations for RewriteRule or ProxyPassMatch rules that re-insert user-supplied request-target data via variable substitution, and rewrite them to avoid non-specific pattern capture.
- Where patching is delayed, disable mod_proxy or restrict the affected rewrite/proxy rules on internet-facing instances.
- Apply vendor and distribution advisories (Debian LTS, Gentoo GLSA) for packaged versions.
Detection
- Inspect proxy and origin access logs for requests containing encoded CRLF (%0d%0a) or unusual whitespace in the request-target that could indicate smuggling attempts.
- Compare proxy logs against backend origin logs for mismatched request counts, unexpected URLs, or requests that appear to originate from the proxy without a corresponding client request.
- Monitor for cache poisoning indicators such as unexpected cached responses or duplicate cache entries tied to proxied paths.
- Alert on anomalous request patterns to RewriteRule or ProxyPassMatch endpoints, including repeated malformed request-targets from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-25690 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-25690), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.