CVE-2016-8743 is an improper-input-validation flaw in Apache HTTP Server's HTTP parser. Vulnerable releases accept non-standard whitespace and prohibited unencoded control characters in HTTP request lines and headers more permissively than required by HTTP grammar, and may also handle whitespace in response lines and headers inconsistently. This can create parser differentials when httpd is deployed in a proxy chain or communicates with an application backend through mod_proxy or CGI. Apache HTTP Server releases before 2.2.32 and 2.4.25 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Apache HTTP Server request-header parsing flaw that can enable response injection and proxy cache poisoning when intermediary or backend systems parse invalid characters differently.
Apache HTTP Server request-header parsing flaw that can cause response injection and proxy cache poisoning when deployed with differently interpreting proxies or backends.
An Apache HTTP Server request-header parsing flaw that can enable response injection and proxy cache poisoning in proxy/backend deployments with differing parsing behavior.
An Apache HTTP Server (httpd) HTTP-request parsing flaw that permits prohibited unencoded characters in request headers. Differential interpretation by a proxy or backend server can enable remote HTTP-response injection and proxy-cache poisoning.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.