CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
371 vulnerabilities with CWE-444
CVE-2021-20220
MEDIUM
Undertow < 2.0.34 and 2.1.0-2.1.6 - HTTP Request Smuggling via Invalid Character Handling
CVSS 4.8
CVE-2021-23339
MEDIUM
Akka-http-core <10.1.14, 10.2.0-10.2.4 - SSRF
CVSS 5.0
CVE-2021-23336
MEDIUM
Python/cpython <3.6.13, <3.7.10, <3.8.8, <3.9.2 - Web Cache Poisoning
CVSS 5.9
CVE-2021-21299
MEDIUM
hyper 0.12.0-0.13.9 and 0.14.0-0.14.2 - HTTP Request Smuggling via Transfer-Encoding Header Mismanagement
CVSS 4.8
CVE-2021-22293
HIGH
Huawei CampusInsight V100R019C10 - HTTP Request Smuggling
CVSS 7.5
CVE-2021-25762
MEDIUM
JetBrains Ktor < 1.4.3 - HTTP Request Smuggling
CVSS 5.3
CVE-2021-21445
MEDIUM
SAP Commerce Cloud 1808, 1811, 1905, 2005, 2011 - HTTP Response Smuggling via Content Type Header
CVSS 5.4
CVE-2020-25097
HIGH
Squid 2.0-4.13 and 5.0-5.0.4 - HTTP Request Smuggling via uri_whitespace Configuration
CVSS 8.6
CVE-2020-28483
HIGH
gin-gonic/gin - HTTP Request Smuggling via X-Forwarded-For Header
CVSS 7.1
CVE-2020-28473
MEDIUM
bottle < 0.12.19 - Web Cache Poisoning via Parameter Cloaking
CVSS 6.8
CVE-2020-17509
HIGH
Apache Traffic Server <8.1.0 - Cache Poisoning
CVSS 7.5
CVE-2020-8287
MEDIUM
Node.js <10.23.1, 12.20.1, 14.15.4, 15.5.1 - SSRF
CVSS 6.5
CVE-2020-35884
MEDIUM
tiny-http < 0.8.0 - HTTP Request Smuggling via Malformed Transfer-Encoding Header
CVSS 6.5
CVE-2020-35863
CRITICAL
hyper < 0.12.34 - HTTP Request Smuggling
CVSS 9.8
CVE-2020-26281
MEDIUM
async-h1 <2.3.0 - Request Smuggling
CVSS 6.8
CVE-2020-28361
MEDIUM
Kamailio < 5.4.0 - HTTP Request Smuggling via Whitespace Bypass in remove_hf Function
CVSS 5.4
CVE-2020-26129
MEDIUM
JetBrains Ktor < 1.4.1 - HTTP Request Smuggling
CVSS 6.5
CVE-2020-7764
MEDIUM
find-my-way <2.2.5 & 3.0.0-3.0.5 - DoS
CVSS 5.9
CVE-2020-25613
HIGH
Ruby WEBrick < 1.6.0 - HTTP Request Smuggling via Transfer-Encoding Header
CVSS 7.5
CVE-2020-10687
MEDIUM
Undertow < 2.2.0.Final - HTTP Request Smuggling via Invalid Characters in HTTP Request
CVSS 4.8
CVE-2020-8201
HIGH
Node.js < 12.18.4-14.11 - Open Redirect
CVSS 7.4
CVE-2020-15810
MEDIUM
Squid < 4.13 and 5.x < 5.0.4 - HTTP Request Smuggling via Relaxed Header Parsing
CVSS 6.5
CVE-2020-9490
HIGH
Apache HTTP Server 2.4.20-2.4.43 - Denial of Service via Crafted Cache-Digest Header
CVSS 7.5
CVE-2020-11993
HIGH
Apache HTTP Server 2.4.20-2.4.43 - HTTP Request Smuggling via HTTP/2 Module Logging
CVSS 7.5
CVE-2020-15049
CRITICAL
Squid < 4.12 and 5.x < 5.0.3 - HTTP Request Smuggling via Content-Length Header
CVSS 9.9
Details
Vulnerabilities
371