CWE-444
356 CVEs • Abstraction: Base
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
CVEs (356)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Enterprise Application Platform UndertowNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling. |
2Debian Redhat3Debian Linux Jboss Enterprise Application PlatformUndertowNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a diffe...Show more |
5Debian EclipseHp+2 more19Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+16 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When present...Show more |
5Debian EclipseHp+2 more17Debian Linux E Series Santricity ManagementE Series Santricity Os Controller+14 moreNov 21, 2024 Jun 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vul...Show more |
2Debian Eclipse2Debian Linux JettyNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space U...Show more |
2Apsis Debian2Debian Linux PoundNov 21, 2024 Jan 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751. |
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and p...Show more |
2Keycloak Redhat2Keycloak Single Sign OnMay 13, 2026 Oct 26, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a m...Show more |
1Ikarussecurity 1Ikarus Antivirus May 13, 2026 Oct 19, 2017 N/A· v4 7.4 HIGH· v3 7.6 HIGH· v2 An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleartext HTTP for updates along with a CRC32 checksum and an update value f...Show more |
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers. |
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as dem...Show more |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Sep 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact. |
AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-the-middle in order to execute code in the machine. |
1Sun 4Java System Application Server Java System Web Proxy ServerJava System Web Server+1 moreApr 23, 2026 Dec 4, 2006 N/A· v4 N/A· v3 6.8 MEDIUM· v2 HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filter...Show more |
1Microsoft 1Internet Information Services Apr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Con...Show more |
2Apache Debian2Debian Linux Http ServerApr 16, 2026 Jul 5, 2005 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTT...Show more |