/claim #12455

Template / PR Information

This PR adds a template for CVE-2023-25690, a critical HTTP Request Smuggling vulnerability in Apache HTTP Server versions 2.4.0 through 2.4.55 when mod_proxy is misconfigured with RewriteRule or ProxyPassMatch using variable substitution.

Validation

  • Tested in a lab environment with Apache 2.4.55 and mod_proxy.
  • Verified via smuggled request evidence (POST /, GET /smuggled) and Apache desync error responses (400, 408, 502, 503).

References

Template Validation

I’ve validated this template locally?

  • YES
  • NO

Additional Details (leave it blank if not applicable)

Additional References:

Claim

Total prize pool $50
Total paid $0
Status Pending
Submitted September 13, 2025
Last updated September 13, 2025

Contributors

MO

Mohamed Mathari

@nocodeventure

100%

Sponsors

PR

ProjectDiscovery

@projectdiscovery

$50