CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

315 vulnerabilities with CWE-444
CVE-2024-6827 HIGH
Gunicorn 21.2.0 - SSRF
CVSS 7.5
CVE-2024-10264 CRITICAL
netease-youdao/qanything <1.4.1 - RCE
CVSS 9.8
CVE-2024-56908 MEDIUM
Perfex Crm <3.2.1 - Auth Bypass
CVSS 6.8
CVE-2024-12397 HIGH
Io.quarkus.http Quarkus-http-core < 5.3.4 - HTTP Request Smuggling
CVSS 7.4
CVE-2024-53008 MEDIUM
HAProxy - Info Disclosure
CVSS 5.3
CVE-2024-9666 MEDIUM
Org.keycloak Keycloak-quarkus-server - HTTP Request Smuggling
CVSS 4.7
CVE-2024-52304 HIGH
aiohttp <3.10.11 - Request Smuggling
CVSS 7.5
CVE-2024-52530 HIGH
Gnome Libsoup < 3.6.0 - HTTP Request Smuggling
CVSS 7.5
CVE-2024-49768 CRITICAL
Waitress - DoS
CVSS 9.1
CVE-2024-44775 HIGH
kmqtt <0.2.7 - DoS
CVSS 7.5
CVE-2024-21281 MEDIUM
Oracle Banking Liquidity Management - HTTP Request Smuggling
CVSS 5.3
CVE-2024-8912 HIGH
Google Cloud Looker < 23.12.123 - HTTP Request Smuggling
CVSS 7.5
CVE-2024-9622 MEDIUM
Org.jboss.resteasy Resteasy-netty4-cdi - HTTP Request Smuggling
CVSS 5.3
CVE-2024-8925 LOW
Php < 8.1.30 - HTTP Request Smuggling
CVSS 3.1
CVE-2024-34535 MEDIUM
Mastodon 4.1.6 - CSRF
CVSS 5.9
CVE-2024-45614 MEDIUM
Puma < 5.6.9 - HTTP Request Smuggling
CVSS 5.4
CVE-2024-42342 MEDIUM
Loway Queuemetrics < 24.05.5 - HTTP Request Smuggling
CVSS 4.3
CVE-2024-27185 CRITICAL
Pagination Class - SSRF
CVSS 9.1
CVE-2024-35538 MEDIUM
Typecho - HTTP Request Smuggling
CVSS 5.3
CVE-2024-41671 HIGH
Pypi Twisted < 24.7.0rc1 - HTTP Request Smuggling
CVSS 8.3
CVE-2024-35161 HIGH
Apache Traffic Server < 8.1.11 - HTTP Request Smuggling
CVSS 7.5
CVE-2024-41110 CRITICAL
Docker < 23.0.15 - HTTP Request Smuggling
CVSS 9.9
CVE-2024-38494 HIGH
PAM - RCE
CVE-2024-22279 MEDIUM
Cloud Foundry <0.297.0 - DoS
CVSS 5.9
CVE-2024-23326 MEDIUM
Envoy < 1.27.6 - HTTP Request Smuggling
CVSS 5.9
Details
Vulnerabilities 315