CVE-2022-31813 is an insufficient verification of data authenticity flaw in Apache HTTP Server mod_proxy affecting versions 2.4.53 and earlier. A client can use the HTTP Connection header's hop-by-hop header mechanism to cause mod_proxy to remove X-Forwarded-* headers, including X-Forwarded-For, before forwarding a request to the origin server. If the origin application uses these headers to enforce IP-address-based authentication or authorization, the missing header can cause the application to incorrectly accept a request.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository is a small proof-of-concept + reproducible lab for CVE-2022-31813 (Apache httpd hop-by-hop header handling) demonstrating an IP-based access control bypass through header manipulation. Key components: - `CVE-2022-31813.py`: Minimal Python client that sends a GET request to a user-supplied URL with crafted headers `X-Real-IP: 127.0.0.1` and `Connection: Close, X-Forwarded-For`. This mirrors the bypass technique described in the README. - `apache/`: - `Dockerfile` pins `httpd:2.4.53`. - `httpd.conf` configures Apache as a reverse proxy to `http://backend:5000/` and sets `RequestHeader set X-Forwarded-For %{REMOTE_ADDR}s`. Modules include `mod_proxy`, `mod_proxy_http`, `mod_headers`, and authz/authn core modules. - `backend/`: - `app.py` is a Flask service that determines the "real" client IP by preferring `X-Forwarded-For`, then `X-Real-IP`, else `remote_addr`. It returns `Admin Access Granted` only when the resolved IP equals `127.0.0.1`, otherwise 403. - `Dockerfile` builds the backend and installs Flask. - `docker-compose.yml` wires the lab: Apache exposed on host `8080`, proxying to the backend on `5000`. Exploit capability/purpose: - Demonstrates a network-based bypass where a client can influence which headers are treated as hop-by-hop (via the `Connection` header) and thereby affect forwarding/interpretation of client IP headers. In this lab, successful exploitation results in the backend believing the request originates from localhost and granting admin access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Apache HTTP Server flaw affecting version 2.4.53 and earlier in which client-controlled Connection hop-by-hop handling can prevent X-Forwarded-* headers from reaching an origin server, potentially bypassing IP-based authentication.
An Apache HTTP Server mod_proxy flaw in which the hop-by-hop mechanism can drop the X-Forwarded-For header.
An Apache HTTP Server mod_proxy flaw in which X-Forwarded-For can be dropped by the hop-by-hop mechanism.
An Apache HTTP Server mod_proxy issue in which the X-Forwarded-For header can be dropped by the hop-by-hop mechanism.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.