CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

370 vulnerabilities with CWE-444
CVE-2026-16728 MEDIUM
undici vulnerable to downstream response desynchronization via retry interceptor
CVSS 4.8
CVE-2026-59898 MEDIUM
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900 MEDIUM
Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-58155 CRITICAL
Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling
CVSS 9.3
CVE-2026-58153 HIGH
Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely
CVSS 8.3
CVE-2026-58150 CRITICAL
Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling
CVSS 10.0
CVE-2026-57834 CRITICAL
Apache Traffic Server: Malformed chunked message body allows request smuggling
CVSS 10.0
CVE-2026-24033 HIGH
Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing
CVSS 7.2
CVE-2026-15328 HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
CVSS 7.4
CVE-2026-15325 HIGH
IBM WebSphere Application Server and Liberty - TRACE Request Smuggling
CVSS 8.7
CVE-2026-15064 HIGH
IBM WebSphere Application Server and Liberty - HTTP Response Smuggling
CVSS 8.7
CVE-2026-67182 HIGH
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
CVSS 7.5
CVE-2026-67181 MEDIUM
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
CVSS 5.4
CVE-2026-66752 MEDIUM
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
CVSS 5.4
CVE-2026-66338 MEDIUM
Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()
CVSS 5.4
CVE-2026-64785 MEDIUM
swift-nio-http2 <1.45.0: HTTP request smuggling & response splitting via unvalidated HEADERS frame chars
CVSS 5.3
CVE-2026-50197 HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests
CVE-2026-59249 MEDIUM
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
CVE-2026-12606 MEDIUM
Eclipse GlassFish - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSS 5.3
CVE-2026-27690 CRITICAL
HTTP Request Smuggling in SAP Approuter
CVSS 9.1
CVE-2026-11541 HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by HTTP request smuggling
CVSS 7.4
CVE-2026-11806 HIGH
IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
CVSS 7.2
CVE-2026-13763 CRITICAL
HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
CVSS 9.8
CVE-2026-13762 CRITICAL
HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF
CVSS 9.8
CVE-2026-58055 MEDIUM
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVSS 5.4
Details
Vulnerabilities 370