VYPR

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

BaseIncomplete

Description

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-273 · CAPEC-33

CVEs mapped to this weakness (428)

page 12 of 22
  • CVE-2021-22960MedNov 3, 2021
    risk 0.42cvss 6.5epss 0.02

    The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.

  • CVE-2021-38512HigAug 10, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.

  • CVE-2020-26129MedNov 16, 2020
    risk 0.42cvss 6.5epss 0.01

    In JetBrains Ktor before 1.4.1, HTTP request smuggling was possible.

  • CVE-2020-25613HigOct 6, 2020
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy…

  • CVE-2020-15810MedSep 2, 2020
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows any client, including browser scripts, to bypass local…

  • CVE-2020-7670HigJun 10, 2020
    risk 0.42cvss 7.5epss 0.01

    agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is…

  • CVE-2020-10719MedMay 26, 2020
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

  • CVE-2020-11076HigMay 22, 2020
    risk 0.42cvss 7.5epss 0.04

    In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.

  • CVE-2019-15272MedOct 2, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper…

  • CVE-2019-16276HigSep 30, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

  • CVE-2019-16869HigSep 26, 2019
    risk 0.42cvss 7.5epss 0.08

    Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

  • CVE-2019-1020012HigJul 29, 2019
    risk 0.42cvss 7.5epss 0.01

    parse-server before 3.4.1 allows DoS after any POST to a volatile class.

  • CVE-2017-2666MedJul 27, 2018
    risk 0.42cvss 6.5epss 0.03

    It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response.…

  • CVE-2026-73494HigSep 14, 2026
    risk 0.41cvss 7.4epss 0.00

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze…

  • CVE-2026-73051MedAug 14, 2026
    risk 0.41cvss —epss 0.00

    actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to…

  • CVE-2026-73495HigAug 12, 2026
    risk 0.41cvss 7.4epss 0.00

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote…

  • CVE-2026-42584HigMay 13, 2026
    risk 0.41cvss 7.3epss 0.01

    Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the…

  • CVE-2026-2332HigApr 14, 2026
    risk 0.41cvss 7.4epss 0.01

    In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty…

  • CVE-2025-12874MedDec 19, 2025
    risk 0.41cvss —epss 0.01

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an…

  • CVE-2024-12397HigDec 12, 2024
    risk 0.41cvss 7.4epss 0.01

    A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values,…