{
  "from_raw": "Eric Covener <covener@apache.org>",
  "from": "Eric Covener <co...@apache.org>",
  "gravatar": "ee9bd44fca004cd144fce0d972679406",
  "to": "an...@apache.org,\n de...@httpd.apache.org",
  "subject": "CVE-2026-63718: Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling",
  "message-id": "<c308fc81-fff2-ae46-ac7f-7017ce3afc81@apache.org>",
  "mid": "75octch0556n7mr3ctcs3q7zw5rs79kk",
  "permalinks": [
    "75octch0556n7mr3ctcs3q7zw5rs79kk",
    "r3c9bc24f6b035e792f7eae0184b15a386c1366ebc07e74bec6580345@<announce.apache.org>"
  ],
  "dbid": "12c3648ec8d982a145ac123a7060dd058c07bc867ec865f75a41e9e7b53dc7dc",
  "cc": "de...@httpd.apache.org",
  "epoch": 1790878116,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/10/01 18:08:36",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.30 through 2.4.68\n\nDescription:\n\nInconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding.\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.68.\n\nCredit:\n\nQing Xu (finder)\n\nReferences:\n\nhttps://httpd.apache.org/security/vulnerabilities_24.html\nhttps://httpd.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-63718\n\nTimeline:\n\n2026-07-14: reported\n2026-10-01: fixed in 2.4.x by r1938691\n2026-10-01: 2.4.69 released\n\n",
  "body_short": "Severity: low \n\nAffected versions:\n\n- Apache HTTP Server 2.4.30 through 2.4.68\n\nDescription:\n\nInconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnera",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3261,
  "id": "75octch0556n7mr3ctcs3q7zw5rs79kk"
}