Vulnerability
CVE-2022-22720
CRITICAL 9.8
CVE-2022-22720 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 152 490 hosts in our data show software it affects on an open port in at least 15 countries.
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
- Published
- 2022-03-14
- Last modified
- 2024-11-21
- CVSS score
- 9.8 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit likelihood (EPSS)
- Not scored
Exposure in our data
152 490 hosts
Hosts whose banner shows an affected software version on a port open at their latest check.
Not counted: 21 367 hosts with this CVE only from an older observation.
Counted 2026-10-05 02:21 UTC
By country
| Germany DE | 32 704 |
| Netherlands NL | 15 841 |
| France FR | 15 624 |
| United States US | 12 858 |
| United Kingdom GB | 12 539 |
| Italy IT | 6 542 |
| Poland PL | 5 510 |
| Czechia CZ | 4 041 |
| Finland FI | 3 756 |
| Lithuania LT | 3 651 |
| Spain ES | 3 610 |
| Ireland IE | 3 562 |
| Sweden SE | 1 925 |
| Japan JP | 1 909 |
| Romania RO | 1 833 |
Affected software seen
| http_server 2.4.52 | 28 853 |
| http_server 2.4.41 | 20 576 |
| http_server 2.4.6 | 13 772 |
| http_server 2 | 13 598 |
| http_server 2.4.29 | 10 652 |
| http_server 2.4.37 | 9 633 |
| http_server 2.4.25 | 6 439 |
| http_server 2.4.18 | 6 088 |
| http_server 2.4.38 | 5 742 |
| http_server 2.4.10 | 5 231 |
| http_server 2.2.22 | 4 759 |
| http_server 2.2.15 | 3 691 |