CWE-444
356 CVEs • Abstraction: Base
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
CVEs (356)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Agendaless Debian2Debian Linux WaitressJun 17, 2026 Mar 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Wa...Show more |
5Apache AppleDebian+2 more8Debian Linux Enterprise Manager Ops CenterFedora+5 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
1Sap 3Content Server Netweaver Application Server AbapWeb DispatcherJun 17, 2026 Feb 9, 2022 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticat...Show more |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Feb 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request whic...Show more |
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet. |
An issue was discovered in VeridiumID VeridiumAD 2.5.3.0. The HTTP request to trigger push notifications for VeridiumAD enrolled users does not enforce proper access control. A user can trigger push notifications for any...Show more |
4Debian FedoraprojectVarnish Software+1 more6Debian Linux FedoraVarnich Cache+3 moreJun 17, 2026 Jan 26, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 conn...Show more |
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so th...Show more |
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets t...Show more |
1Imperva 1Web Application Firewall Jun 17, 2026 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind...Show more |
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 r...Show more |
5Debian NetappNetty+2 more18Banking Deposits And Lines Of Credit Servicing Banking Party ManagementBanking Platform+15 moreJun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are...Show more |
1Tp Link 1Archer Ax10 V1 Firmware Jul 9, 2026 Dec 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet. |
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of...Show more |
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ign...Show more |
1Asus 18Gt Ax11000 Firmware Rt Ax3000 FirmwareRt Ax55 Firmware+15 moreJul 9, 2026 Nov 19, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDI...Show more |
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is...Show more |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 15, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. |
Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a different issue than CVE-2021-33056. |
3Debian LlhttpOracle3Debian Linux GraalvmLlhttpJun 17, 2026 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. |