VYPR

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

BaseIncomplete

Description

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-273 · CAPEC-33

CVEs mapped to this weakness (386)

page 13 of 20
  • CVE-2026-1525MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is…

  • CVE-2025-69224MedJan 5, 2026
    risk 0.35cvss 6.5epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the…

  • CVE-2025-47905MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.00

    Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

  • CVE-2025-30346MedMar 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

  • CVE-2024-53008MedNov 28, 2024
    risk 0.35cvss 5.3epss 0.01

    Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may…

  • CVE-2024-9622MedOct 8, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE…

  • CVE-2024-23829MedJan 29, 2024
    risk 0.35cvss 6.5epss 0.01

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to…

  • CVE-2023-46137MedOct 25, 2023
    risk 0.35cvss 5.3epss 0.01

    Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled…

  • CVE-2023-30910MedOct 9, 2023
    risk 0.35cvss 5.4epss 0.00

    HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests. 

  • CVE-2023-27491MedApr 4, 2023
    risk 0.35cvss 5.4epss 0.01

    Envoy is an open source edge and service proxy designed for cloud-native applications. Compliant HTTP/1 service should reject malformed request lines. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, There is a possibility that non compliant HTTP/1 service may allow…

  • CVE-2021-43797MedDec 9, 2021
    risk 0.35cvss 6.5epss 0.03

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It…

  • CVE-2021-41267MedNov 24, 2021
    risk 0.35cvss 6.5epss 0.01

    Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "Cache poisoning" attacks. In…

  • CVE-2021-31923MedSep 24, 2021
    risk 0.35cvss 5.3epss 0.01

    Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.

  • CVE-2021-34559MedAug 31, 2021
    risk 0.35cvss 5.4epss 0.01

    In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in cached pages to arbitrary strings.

  • CVE-2021-25762MedFeb 3, 2021
    risk 0.35cvss 5.3epss 0.01

    In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.

  • CVE-2021-21445MedJan 12, 2021
    risk 0.35cvss 5.4epss 0.01

    SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead…

  • CVE-2020-35884MedDec 31, 2020
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

  • CVE-2020-28361MedNov 18, 2020
    risk 0.35cvss 5.4epss 0.01

    Kamailio before 5.4.0, as used in Sip Express Router (SER) in Sippy Softswitch 4.5 through 5.2 and other products, allows a bypass of a header-removal protection mechanism via whitespace characters. This occurs in the remove_hf function in the Kamailio textops module. Particular…

  • CVE-2020-7622MedApr 6, 2020
    risk 0.35cvss 6.5epss 0.02

    This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.

  • CVE-2020-10112MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies…