CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

370 vulnerabilities with CWE-444
CVE-2025-0752 HIGH
OpenShift Service Mesh <2.6.3, <2.5.6 - SSRF
CVSS 7.1
CVE-2024-56523 CRITICAL
Radware Cloud WAF <2025-05-07 - Auth Bypass
CVSS 9.1
CVE-2024-33452 HIGH
OpenResty lua-nginx-module < 0.10.26 - HTTP Request Smuggling via HEAD Request
CVSS 7.7
CVE-2024-29643 CRITICAL
croogo 3.0.2 - Host Header Injection via Feed RSS Component
CVSS 9.1
CVE-2024-53868 HIGH
Apache Traffic Server <9.2.10-10.0.5 - Request Smuggling
CVSS 7.5
CVE-2024-6827 HIGH
Gunicorn < 22.0.0 - HTTP Request Smuggling via Transfer-Encoding Header
CVSS 7.5
CVE-2024-10264 CRITICAL
netease-youdao/qanything <1.4.1 - RCE
CVSS 9.8
CVE-2024-56908 MEDIUM
Perfex CRM < 3.2.1 - Authenticated Arbitrary File Upload via upload_sales_file rel_id Parameter
CVSS 6.8
CVE-2024-12397 HIGH
Quarkus-HTTP < 5.3.4 - HTTP Request Smuggling via Cookie Parsing
CVSS 7.4
CVE-2024-53008 MEDIUM
HAProxy 2.6 < 2.6.18, 2.8 < 2.8.10, 2.9 < 2.9.9, 3.0 < 3.0.2 - HTTP Request Smuggling
CVSS 5.3
CVE-2024-9666 MEDIUM
Keycloak - Denial of Service via Proxy Header Handling
CVSS 4.7
CVE-2024-52304 HIGH
aiohttp <3.10.11 - Request Smuggling
CVSS 7.5
CVE-2024-52530 HIGH
GNOME libsoup < 3.6.0 - HTTP Request Smuggling via Null Byte in Header Names
CVSS 7.5
CVE-2024-49768 CRITICAL
Waitress 2.0.0-3.0.0 - Time-of-check Time-of-use Race Condition via HTTP Pipelining
CVSS 9.1
CVE-2024-44775 HIGH
kmqtt 0.2.7 - Denial of Service via Crafted MQTT CONNECT Packet
CVSS 7.5
CVE-2024-21281 MEDIUM
Oracle Banking Liquidity Management 14.7.0.6.0 - HTTP Request Smuggling
CVSS 5.3
CVE-2024-8912 HIGH
Google Cloud Looker 23.12-23.12.122 - Unauthenticated HTTP Request Smuggling
CVSS 7.5
CVE-2024-9622 MEDIUM
resteasy-netty4-cdi - Denial of Service via HTTP Request Smuggling
CVSS 5.3
CVE-2024-8925 LOW
PHP 8.1.0-8.1.29 - HTTP Request Smuggling via Multipart Form Data Parsing
CVSS 3.1
CVE-2024-34535 MEDIUM
Mastodon < 4.1.16 - HTTP Request Smuggling via Crafted Header
CVSS 5.9
CVE-2024-45614 MEDIUM
Puma < 5.6.9 - Authorization Bypass via Underscore Header Clobbering
CVSS 5.4
CVE-2024-42342 MEDIUM
Loway QueueMetrics 22.11.6-24.05.5 - HTTP Request Smuggling
CVSS 4.3
CVE-2024-27185 CRITICAL
Joomla Pagination - Cache Poisoning
CVSS 9.1
CVE-2024-35538 MEDIUM
Typecho 1.3.0 - Client IP Spoofing via X-Forwarded-For or Client-Ip Headers
CVSS 5.3
CVE-2024-41671 HIGH
Twisted < 24.7.0rc1 - HTTP Request Smuggling via Pipelined Request Mismanagement
CVSS 8.3
Details
Vulnerabilities 370