CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

315 vulnerabilities with CWE-444
CVE-2023-23691 HIGH
Dell Powervault Me5012 Firmware < me5.1.1.0.5 - HTTP Request Smuggling
CVSS 8.1
CVE-2022-39163 MEDIUM
IBM Cognos Controller < 11.0.1 - HTTP Request Smuggling
CVSS 4.7
CVE-2022-36760 CRITICAL
Apache HTTP Server < 2.4.55 - HTTP Request Smuggling
CVSS 9.0
CVE-2022-41721 HIGH
MaxBytesHandler - SSRF
CVSS 7.5
CVE-2022-35256 MEDIUM
Nodejs Node.js < 14.14.0 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-38114 MEDIUM
SolarWinds Security Event Manager - HTTP Request Smuggling and XSS
CVSS 6.1
CVE-2022-45059 HIGH
Varnish Cache < 7.1.2 - HTTP Request Smuggling
CVSS 7.5
CVE-2022-42252 HIGH
Apache Tomcat < 8.5.83 - HTTP Request Smuggling
CVSS 7.5
CVE-2022-2880 HIGH
Go ReverseProxy - SSRF
CVSS 7.5
CVE-2022-21826 MEDIUM
Ivanti Connect Secure < 9.1 - HTTP Request Smuggling
CVSS 5.4
CVE-2022-2466 CRITICAL
Quarkus < 2.10.4 - HTTP Request Smuggling
CVSS 9.8
CVE-2022-33988 HIGH
dproxy-nexgen - Info Disclosure
CVSS 7.5
CVE-2022-1705 MEDIUM
GO < 1.17.12 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-20713 MEDIUM
Cisco ASA/FTD - XSS
CVSS 4.3
CVE-2022-25763 HIGH
Apache Traffic Server < 8.1.5 - HTTP Request Smuggling
CVSS 7.5
CVE-2022-31109 HIGH
laminas-diactoros - XSS
CVSS 7.2
CVE-2022-32215 MEDIUM
Llhttp < 14.20.1 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-32214 MEDIUM
Llhttp < 2.1.5 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-32213 MEDIUM
Llhttp < 2.1.5 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-31081 HIGH
HTTP::Daemon <6.15 - Privilege Escalation
CVSS 7.3
CVE-2022-26377 HIGH
Apache HTTP Server <2.4.53 - SSRF
CVSS 7.5
CVE-2022-29361 CRITICAL
Pallets Werkzeug <2.1.0 - SSRF
CVSS 9.8
CVE-2022-0552 MEDIUM
Netty-codec-http - Open Redirect
CVSS 5.9
CVE-2022-24801 HIGH
Twisted < 22.4.0 - HTTP Request Smuggling
CVSS 8.1
CVE-2022-24790 CRITICAL
Puma < 4.3.12 - HTTP Request Smuggling
CVSS 9.1
Details
Vulnerabilities 315