CVE-2023-25690 is an HTTP request splitting/smuggling vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.55. It affects deployments that enable mod_proxy and use RewriteRule or ProxyPassMatch configurations whose insufficiently specific pattern captures user-controlled request-target data and reinserts it into the proxied request target through variable substitution. Crafted request-target input can cause inconsistent request parsing between the proxy and its backend origin.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This four-file repository contains a standalone Python 3 exploit script, smuggle_rce.py, plus README, license, and gitignore files. The script targets CVE-2023-25690 in vulnerable Apache HTTP Server mod_rewrite/mod_proxy deployments. It builds a fully formed backend POST request, percent-encodes CRLF delimiters, and embeds it into an outer GET request sent over a raw TCP socket to an operator-supplied front-end target (default port 80). The inner request uses Host: 127.0.0.1:8080 by default and targets /gen.php, enabling a request to be smuggled past the proxy to an internal backend. It is tailored to the TryHackMe Contrabando scenario but exposes command-line options for target port, backend port, outer path, backend path, and vulnerable parameter. The exploit does not gain execution from CVE-2023-25690 alone: it additionally requires a backend endpoint that passes the selected POST parameter into a shell command. It injects a double-Base64-encoded Bash reverse shell and prints both the constructed request and received server response. No external framework or dependencies are used; the script relies only on Python socket, argparse, and base64 standard-library modules.
This repository is a multi-challenge CTF portfolio rather than a single exploit. It contains several standalone vulnerable applications, Docker/Vercel deployment files, and a few working exploit/solve scripts. The main exploit capabilities present in code are: (1) UDP-based request boundary abuse in HUUP via a custom UDP front end forwarding to a local Flask server; (2) OS argument/command injection in argument through `os.system()` invoking a custom tar wrapper with attacker-controlled filenames; (3) stored XSS plus privileged command execution in not-a-problem, where attacker-controlled stats are rendered unsafely and an admin bot with a secret cookie can reach `/api/date`, which concatenates user input into `date`; (4) predictable JWT secret derivation and arbitrary file read in random, with included scripts that brute-force the secret from leaked uptime and then request `/proc/self/cwd/flag.txt`; (5) XSS filter bypass and admin-bot abuse in socialmedia2, including a provided payload and automation script; (6) trivial header spoofing in spoof via `User-Agent == 'Lorem ipsum'`; and (7) two simpler disclosure challenges in pleaseavoid and source. Repository structure is organized by challenge directory, each usually containing a README, app code, deployment config, and sometimes a solve script. The most actionable exploit code is in `random/solve.py`, `random/solve_live.py`, `not-a-problem/solve.py`, and `socialmedia2/solve_social.py`, while `argument/server.py`, `argument/tar`, `HUUP/udp_server.py`, `not-a-problem/server.py`, `random/server.py`, `socialmedia2/unhackable2.py`, and `spoof/spoof.py` contain the vulnerable logic itself.
This repository provides a comprehensive proof-of-concept (POC) for CVE-2023-25690, a critical HTTP request smuggling vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.55 when using mod_proxy with certain RewriteRule or ProxyPassMatch configurations. The repository includes a detailed README explaining the vulnerability, its exploitation via CRLF injection, and the impact of successful exploitation. The lab setup is fully dockerized, with a frontend Apache proxy (configured in httpd.conf) and a backend PHP server (categories.php) that contains both public and hidden functionality. The exploit demonstrates how an attacker can craft a malicious HTTP request that, when processed by the vulnerable proxy, results in a smuggled internal request to the backend, potentially accessing hidden endpoints or triggering backend actions (such as DNS lookups). The repository is structured for educational and testing purposes, with clear separation between frontend and backend components, and includes all necessary configuration files for reproducing the vulnerability in a controlled environment.
This repository provides a comprehensive proof-of-concept (POC) lab for CVE-2023-25690, a critical HTTP Request Smuggling vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.55 when using mod_proxy with certain RewriteRule or ProxyPassMatch configurations. The repository is structured as a Dockerized lab with separate frontend (proxy) and backend (PHP) services. The frontend uses a vulnerable Apache configuration that proxies requests to the backend, which contains a PHP script with both public and hidden (triggered by a 'secret' parameter) functionality. The README.md details the vulnerability, provides step-by-step exploitation instructions, and explains how CRLF injection in the URL can be used to smuggle requests to the backend, potentially accessing internal-only features. The exploit demonstrates how an attacker can use HTTP request splitting to bypass proxy controls and interact with backend services directly. The repository includes all necessary configuration files and code to reproduce the vulnerability in a controlled environment.
This repository provides a proof-of-concept exploit for CVE-2023-25690, a vulnerability in Apache HTTP Server (versions 2.4.0 to 2.4.55) that allows HTTP Request Smuggling attacks when mod_proxy is enabled with certain RewriteRule or ProxyPassMatch configurations. The main exploit script (CVE-2023-25690.py) constructs a specially crafted HTTP request by encoding control characters and appending a secondary GET request, exploiting the server's parsing logic to bypass proxy restrictions. The exploit targets a simulated lab environment defined in the 'lab' directory, which uses Docker to set up a vulnerable Apache proxy and backend server. The backend exposes endpoints such as /admin.php and /categories.php, with /admin.php containing functionality that can execute system commands via the 'secret' parameter. The README.md provides detailed instructions and background, including network topology and exploitation steps. The exploit demonstrates how an attacker can use HTTP Request Smuggling to access internal endpoints (like /admin.php) that are otherwise restricted by the proxy, potentially leading to unauthorized command execution on the backend server. The repository includes configuration files for Docker, Apache, and PHP scripts to facilitate local testing and demonstration of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific Apache HTTP Server vulnerability referenced as an example of how to provide precise remediation guidance in a VAPT report.
Apache HTTP Server HTTP request-splitting vulnerability when mod_rewrite and mod_proxy are used together.
Apache HTTP Server HTTP request-splitting vulnerability involving mod_rewrite and mod_proxy.
A vulnerability in Apache httpd that may impact AEM customers using non-default proxy configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.