CVE-CVE-2023-25690
Severity
CRITICAL
CVSS Score
9.8
Description
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "h...
PoCs for CVE-CVE-2023-25690
cve-2023-25690-smuggler
SQL Injection
Python
0
roshanrajbanshi
2026-09-25