CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
315 vulnerabilities with CWE-444
CVE-2025-58068
CRITICAL
Eventlet < 0.40.3 - HTTP Request Smuggling
CVSS 9.1
CVE-2025-54142
MEDIUM
Akamai Ghost <2025-07-21 - HTTP Request Smuggling
CVSS 4.0
CVE-2025-32094
MEDIUM
Akamai Ghost <2025-03-26 - SSRF
CVSS 4.0
CVE-2025-52892
MEDIUM
Espocrm < 9.1.7 - HTTP Request Smuggling
CVSS 4.5
CVE-2025-53643
HIGH
AIOHTTP <3.12.14 - Request Smuggling
CVSS 7.5
CVE-2025-53628
HIGH
cpp-httplib <0.20.1 - Memory Corruption
CVSS 8.8
CVE-2025-49826
HIGH
Vercel Next.js < 15.1.8 - HTTP Request Smuggling
CVSS 7.5
CVE-2025-49005
LOW
Vercel Next.js < 15.3.3 - HTTP Request Smuggling
CVSS 3.7
CVE-2025-6442
MEDIUM
Ruby-lang Webrick < 1.8.2 - HTTP Request Smuggling
CVSS 5.9
CVE-2025-41235
HIGH
Org.springframework.cloud Spring-clou... - HTTP Request Smuggling
CVSS 8.6
CVE-2025-4366
MEDIUM
Cloudflare Pingora < 0.5.0 - HTTP Request Smuggling
CVSS 6.1
CVE-2025-23167
MEDIUM
Node.js 20 - Request Smuggling
CVSS 6.5
CVE-2025-4600
HIGH
Google Cloud Classic App LB - RCE
CVSS 7.5
CVE-2025-47905
MEDIUM
Varnish Cache <7.6.3-7.7.1 & Varnish Enterprise <6.0.13r14 - Open R...
CVSS 5.4
CVE-2025-43859
CRITICAL
Pypi H11 < 0.16.0 - HTTP Request Smuggling
CVSS 9.1
CVE-2025-1386
MEDIUM
Clickhouse CH < 0.65.0 - HTTP Request Smuggling
CVSS 4.9
CVE-2025-31137
HIGH
React-router Express < 7.4.1 - HTTP Request Smuggling
CVSS 7.5
CVE-2025-30346
MEDIUM
Varnish Cache <7.6.2 - Open Redirect
CVSS 5.4
CVE-2025-29904
MEDIUM
JetBrains Ktor <3.1.1 - SSRF
CVSS 5.3
CVE-2025-1867
CRITICAL
libhv <1.3.3 - SSRF
CVE-2025-0752
HIGH
OpenShift Service Mesh <2.6.3, <2.5.6 - SSRF
CVSS 7.1
CVE-2024-56523
CRITICAL
Radware Cloud WAF <2025-05-07 - Auth Bypass
CVSS 9.1
CVE-2024-33452
HIGH
Openresty Lua-nginx-module < 0.10.26 - HTTP Request Smuggling
CVSS 7.7
CVE-2024-29643
CRITICAL
Croogo <3.0.2 - SSRF
CVSS 9.1
CVE-2024-53868
HIGH
Apache Traffic Server <9.2.10-10.0.5 - Request Smuggling
CVSS 7.5
Details
Vulnerabilities
315