CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
370 vulnerabilities with CWE-444
CVE-2026-16728
MEDIUM
undici vulnerable to downstream response desynchronization via retry interceptor
CVSS 4.8
CVE-2026-59898
MEDIUM
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-59900
MEDIUM
Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
CVE-2026-58155
CRITICAL
Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling
CVSS 9.3
CVE-2026-58153
HIGH
Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely
CVSS 8.3
CVE-2026-58150
CRITICAL
Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling
CVSS 10.0
CVE-2026-57834
CRITICAL
Apache Traffic Server: Malformed chunked message body allows request smuggling
CVSS 10.0
CVE-2026-24033
HIGH
Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing
CVSS 7.2
CVE-2026-15328
HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests
CVSS 7.4
CVE-2026-15325
HIGH
IBM WebSphere Application Server and Liberty - TRACE Request Smuggling
CVSS 8.7
CVE-2026-15064
HIGH
IBM WebSphere Application Server and Liberty - HTTP Response Smuggling
CVSS 8.7
CVE-2026-67182
HIGH
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection
CVSS 7.5
CVE-2026-67181
MEDIUM
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
CVSS 5.4
CVE-2026-66752
MEDIUM
tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling
CVSS 5.4
CVE-2026-66338
MEDIUM
Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()
CVSS 5.4
CVE-2026-64785
MEDIUM
swift-nio-http2 <1.45.0: HTTP request smuggling & response splitting via unvalidated HEADERS frame chars
CVSS 5.3
CVE-2026-50197
HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests
CVE-2026-59249
MEDIUM
Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections
CVE-2026-12606
MEDIUM
Eclipse GlassFish - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSS 5.3
CVE-2026-27690
CRITICAL
HTTP Request Smuggling in SAP Approuter
CVSS 9.1
CVE-2026-11541
HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by HTTP request smuggling
CVSS 7.4
CVE-2026-11806
HIGH
IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability
CVSS 7.2
CVE-2026-13763
CRITICAL
HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
CVSS 9.8
CVE-2026-13762
CRITICAL
HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF
CVSS 9.8
CVE-2026-58055
MEDIUM
nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVSS 5.4
Details
Vulnerabilities
370