VYPR

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

BaseIncomplete

Description

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-273 · CAPEC-33

CVEs mapped to this weakness (429)

page 14 of 22
  • CVE-2024-22279MedJun 10, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale.

  • CVE-2020-28473MedJan 18, 2021
    risk 0.37cvss 6.8epss 0.02

    The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the…

  • CVE-2026-58047MedJul 31, 2026
    risk 0.36cvss —epss 0.01

    HTTP Smuggling in cPanel allows potential leak of credentials.

  • CVE-2026-85078MedSep 17, 2026
    risk 0.35cvss 6.5epss 0.01

    Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place…

  • CVE-2026-89044MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split…

  • CVE-2026-51376MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh gossip cache

  • CVE-2026-67181MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's…

  • CVE-2026-66752MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply…

  • CVE-2026-66338MedJul 24, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a…

  • CVE-2026-29057MedMar 18, 2026
    risk 0.35cvss 6.5epss 0.01

    Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could…

  • CVE-2026-32240MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP…

  • CVE-2026-32239MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This…

  • CVE-2026-1525MedMar 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is…

  • CVE-2025-69224MedJan 5, 2026
    risk 0.35cvss 6.5epss 0.00

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII characters. If a pure Python version of AIOHTTP is installed (i.e. without the…

  • CVE-2025-47905MedMay 13, 2025
    risk 0.35cvss 5.4epss 0.00

    Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

  • CVE-2025-30346MedMar 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests.

  • CVE-2024-53008MedNov 28, 2024
    risk 0.35cvss 5.3epss 0.01

    Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may…

  • CVE-2024-9622MedOct 8, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE…

  • CVE-2024-23829MedJan 29, 2024
    risk 0.35cvss 6.5epss 0.01

    aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to…

  • CVE-2023-46137MedOct 25, 2023
    risk 0.35cvss 5.3epss 0.01

    Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled…