CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

371 vulnerabilities with CWE-444
CVE-2022-31081 HIGH
HTTP::Daemon <6.15 - Privilege Escalation
CVSS 7.3
CVE-2022-26377 HIGH
Apache HTTP Server 2.4.0-2.4.53 - HTTP Request Smuggling via mod_proxy_ajp
CVSS 7.5
CVE-2022-29361 CRITICAL
Werkzeug < 2.1.0 - HTTP Request Smuggling via Crafted Request Body
CVSS 9.8
CVE-2022-0552 MEDIUM
origin-aggregated-logging 3.11 - HTTP Request Smuggling via Incomplete Netty Codec Fix
CVSS 5.9
CVE-2022-24801 HIGH
Twisted < 22.4.0 - HTTP Request Smuggling via Non-Conformant HTTP Request Parsing
CVSS 8.1
CVE-2022-24790 CRITICAL
Puma < 4.3.12 and 5.0.0-5.6.4 - HTTP Request Smuggling via Proxy Request Parsing Discrepancy
CVSS 9.1
CVE-2022-24766 CRITICAL
mitmproxy < 7.0.4 and >=8.0.0 - HTTP Request Smuggling
CVSS 9.8
CVE-2022-24761 HIGH
Waitress < 2.1.1 - HTTP Request Smuggling via Invalid HTTP Request Parsing
CVSS 7.5
CVE-2022-22720 CRITICAL
Apache HTTP Server < 2.4.52 - HTTP Request Smuggling via Inbound Connection Handling
CVSS 9.8
CVE-2022-22536 CRITICAL KEV
SAP Content Server 7.53 - Unauthenticated HTTP Request Smuggling
CVSS 10.0
CVE-2022-22532 CRITICAL
SAP NetWeaver Application Server Java - Memory Corruption
CVSS 9.8
CVE-2022-23959 CRITICAL
Varnish Cache HTTP Request Smuggling (6.6.2, 7.0.2, 6.0.10, 4.1.11r6, 6.0.9r4)
CVSS 9.1
CVE-2022-22691 MEDIUM
Umbraco CMS < 9.2.0 - Password Reset Token Disclosure via Host Header Manipulation
CVSS 6.8
CVE-2022-22690 HIGH
Umbraco CMS < 9.2.0 - Persistent URL Overwrite via UmbracoApplicationUrl Manipulation
CVSS 8.6
CVE-2021-46825 CRITICAL
Symantec ASG & ProxySG - Open Redirect
CVSS 9.1
CVE-2021-25220 MEDIUM
Juniper Junos < 19.3 - HTTP Request Smuggling
CVSS 6.8
CVE-2021-41442 HIGH
D-Link DIR-X1860 Firmware < 1.03 - Unauthenticated Denial of Service via HTTP Request Smuggling
CVSS 7.5
CVE-2021-42791 HIGH
VeridiumID VeridiumAD 2.5.3.0 - Unauthenticated Push Notification Spoofing and Certificate Theft
CVSS 7.3
CVE-2021-45468 CRITICAL
Imperva Web Application Firewall < 2021-12-23 - Unauthenticated HTTP Request Smuggling via Gzip Content-Encoding
CVSS 9.8
CVE-2021-41451 HIGH
TP-Link Archer AX10 Firmware < V1_211117 - Unauthenticated HTTP Request Smuggling via HTTP/0.9 Response
CVSS 7.5
CVE-2021-43797 MEDIUM
Netty <4.1.71.Final - HTTP Request Smuggling
CVSS 6.5
CVE-2021-41450 HIGH
TP-Link Archer AX10 v1 Firmware < 211117 - Unauthenticated Denial of Service via HTTP Request Smuggling
CVSS 7.5
CVE-2021-37253 HIGH
M-Files Web < 20.10.9524.1 - Denial of Service via Overlapping HTTP Range Headers
CVSS 7.5
CVE-2021-41267 MEDIUM
Symfony/Http-Kernel - Info Disclosure
CVSS 6.5
CVE-2021-41436 HIGH
ASUS GT-AX11000 < 3.0.0.4.386.45898 - Unauthenticated DoS via HTTP Request Smuggling
CVSS 7.5
Details
Vulnerabilities 371