Since we could reproduce it in plucky that is version 2.4.63, same as upstream, do you mind to report this bug upstream: https://httpd.apache.org/bug_report.html
Thanks a lot for report it! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2103723 Title: Fix for CVE-2024-38474 also blocks %3f in appended query strings To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2103723/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs