CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

370 vulnerabilities with CWE-444
CVE-2026-48743 HIGH
Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length
CVSS 7.5
CVE-2026-52845 HIGH
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
CVSS 8.1
CVE-2026-48746 CRITICAL
vLLM: OpenAI auth bypass
CVSS 9.1
CVE-2026-53538 LOW
Python-Multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVSS 3.7
CVE-2026-8646 HIGH
IBM WebSphere Application Server and Liberty - HTTP Request Smuggling
CVSS 7.4
CVE-2026-48979 HIGH
PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling
CVSS 7.5
CVE-2026-54388 CRITICAL
Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers
CVSS 9.1
CVE-2026-54387 CRITICAL
Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization
CVSS 9.1
CVE-2026-50020 MEDIUM
Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
CVSS 5.3
CVE-2026-46342 MEDIUM
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
CVSS 5.4
CVE-2026-6338 MEDIUM
HTTP request smuggling in Kong Enteprise Gateway
CVE-2026-41853 MEDIUM
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
CVSS 5.3
CVE-2026-44546 LOW
Header injection via WebSocket upgrade parser differential allows ASGI scope header spoofing
CVSS 3.7
CVE-2026-50052 LOW
Vinyl Cache - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE-2026-49753 MEDIUM
HTTP response smuggling in Mint HTTP/1 client via lenient Content-Length parsing
CVE-2026-45372 CRITICAL
cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
CVSS 9.9
CVE-2026-6324 MEDIUM
Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
CVSS 4.8
CVE-2026-47676 MEDIUM
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
CVSS 5.3
CVE-2026-48710 MEDIUM
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVSS 6.5
CVE-2026-8620 HIGH
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities when using when using Web Server Plug-ins
CVSS 7.5
CVE-2026-42585 MEDIUM
Netty: HTTP Request Smuggling due to malformed Transfer-Encoding
CVSS 6.5
CVE-2026-42584 HIGH
Netty: HttpClientCodec response desynchronization
CVSS 7.3
CVE-2026-42581 MEDIUM
Netty: HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
CVSS 5.8
CVE-2026-42580 MEDIUM
Netty: HTTP Request Smuggling due to incorrect chunk size parsing
CVSS 6.5
CVE-2026-41417 MEDIUM
Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()
CVSS 5.3
Details
Vulnerabilities 370