Vulnerability

CVE-2022-22720

CRITICAL 9.8

CVE-2022-22720 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 152 490 hosts in our data show software it affects on an open port in at least 15 countries.

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Published
2022-03-14
Last modified
2024-11-21
CVSS score
9.8 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit likelihood (EPSS)
Not scored

Exposure in our data

152 490 hosts

Hosts whose banner shows an affected software version on a port open at their latest check.

Not counted: 21 367 hosts with this CVE only from an older observation.

Counted 2026-10-05 02:21 UTC

By country

Germany DE32 704
Netherlands NL15 841
France FR15 624
United States US12 858
United Kingdom GB12 539
Italy IT6 542
Poland PL5 510
Czechia CZ4 041
Finland FI3 756
Lithuania LT3 651
Spain ES3 610
Ireland IE3 562
Sweden SE1 925
Japan JP1 909
Romania RO1 833

Affected software seen

http_server 2.4.5228 853
http_server 2.4.4120 576
http_server 2.4.613 772
http_server 213 598
http_server 2.4.2910 652
http_server 2.4.379 633
http_server 2.4.256 439
http_server 2.4.186 088
http_server 2.4.385 742
http_server 2.4.105 231
http_server 2.2.224 759
http_server 2.2.153 691