VYPR

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

BaseIncomplete

Description

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-273 · CAPEC-33

CVEs mapped to this weakness (386)

page 2 of 20
  • CVE-2023-27238CriMay 12, 2023
    risk 0.64cvss 9.8epss 0.01

    LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.

  • CVE-2023-29141CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.

  • CVE-2022-2466CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

  • CVE-2022-22532CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This…

  • CVE-2021-45468CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.04

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.

  • CVE-2020-1944CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.03

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

  • CVE-2019-17565CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.03

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

  • CVE-2019-17559CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.03

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

  • CVE-2016-10711CriJan 29, 2018
    risk 0.64cvss 9.8epss 0.03

    Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.

  • CVE-2023-46846CriNov 3, 2023
    risk 0.61cvss 9.3epss 0.06

    SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

  • CVE-2023-25725CriFeb 14, 2023
    risk 0.60cvss 9.1epss 0.05

    HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers…

  • CVE-2026-9190CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs…

  • CVE-2024-56523CriMay 12, 2025
    risk 0.59cvss 9.1epss 0.01

    Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.

  • CVE-2024-29643CriApr 18, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

  • CVE-2023-29476CriDec 14, 2024
    risk 0.59cvss 9.1epss 0.00

    In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.

  • CVE-2024-27185CriAug 20, 2024
    risk 0.59cvss 9.1epss 0.00

    The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

  • CVE-2024-41110CriJul 24, 2024
    risk 0.59cvss 9.9epss 0.17

    Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base…

  • CVE-2023-33934CriAug 9, 2023
    risk 0.59cvss 9.1epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

  • CVE-2023-33193CriMay 30, 2023
    risk 0.59cvss 9.1epss 0.02

    Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby…

  • CVE-2022-36760CriJan 17, 2023
    risk 0.59cvss 9.0epss 0.02

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version…