CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

370 vulnerabilities with CWE-444
CVE-2024-35161 HIGH
Apache Traffic Server 8.0.0-8.1.10 and 9.0.0-9.2.4 - HTTP Request Smuggling via Malformed Chunked Trailer
CVSS 7.5
CVE-2024-41110 CRITICAL
Docker 19.03.0-27.1.0 - Authorization Bypass via API Request Body Omission
CVSS 9.9
CVE-2024-38494 HIGH
Broadcom Symantec PAM 3.4.6 and 4.1.0-4.1.7 - Authenticated Remote Command Execution
CVE-2024-22279 MEDIUM
Cloud Foundry <0.297.0 - DoS
CVSS 5.9
CVE-2024-23326 MEDIUM
Envoy < 1.27.6 - Request Smuggling via Incorrect Protocol Upgrade Handling
CVSS 5.9
CVE-2024-23316 HIGH
Ping Identity PingAccess <8.0.1 - Open Redirect
CVE-2024-34350 HIGH
Next.js 13.4.0-13.5.0 - HTTP Request Smuggling via Rewrites Feature
CVSS 7.5
CVE-2024-27982 MEDIUM
Node < 18.20.1, 19.x, < 20.12.1, < 21.7.2 - HTTP Request Smuggling via Malformed Content-Length Header
CVSS 6.5
CVE-2024-32638 MEDIUM
Apache APISIX 3.8.0-3.9.0 - HTTP Request Smuggling via Forward-Auth Plugin
CVSS 6.3
CVE-2024-21088 HIGH
Oracle E-Business Suite 12.2.4-12.2.12 - Unauthenticated HTTP Request Smuggling in Import Utility
CVSS 7.5
CVE-2024-1135 HIGH
Gunicorn < 22.0.0 - HTTP Request Smuggling via Transfer-Encoding Header Mismanagement
CVSS 7.5
CVE-2024-24795 MEDIUM
Apache HTTP Server 2.4.0-2.4.58 - HTTP Response Splitting via Malicious Response Headers
CVSS 6.3
CVE-2024-27922 CRITICAL
TOMP Bare Server < 2.0.2 - HTTP Request Smuggling
CVSS 9.8
CVE-2024-22081 CRITICAL
Espec G5 <1.1.4.15 - Memory Corruption
CVSS 9.8
CVE-2024-27439 MEDIUM
Apache Wicket <9.16.0 - Auth Bypass
CVSS 6.5
CVE-2024-20915 MEDIUM
Oracle Application Object Library 12.2.3-12.2.13 - Unauthenticated Partial Denial of Service via HTTP Request Smuggling
CVSS 5.3
CVE-2024-23452 HIGH
Apache bRPC 0.9.5-1.7.0 - HTTP Request Smuggling via Transfer-Encoding and Content-Length Header
CVSS 7.5
CVE-2024-23829 MEDIUM
aiohttp < 3.9.2 - HTTP Request Smuggling via Inconsistent HTTP Parser Validation
CVSS 6.5
CVE-2024-21647 MEDIUM
Puma < 5.6.8 and 6.0.0-6.4.2 - HTTP Request Smuggling via Chunked Transfer Encoding
CVSS 5.9
CVE-2023-53878 MEDIUM
Member Login Script 3.3 - HTTP Request Smuggling via Content-Length Header Parsing
CVE-2023-29476 CRITICAL
Menlo On-Premise Appliance <2.88 - Info Disclosure
CVSS 9.1
CVE-2023-4639 HIGH
Undertow Cookie Parsing - HttpOnly Cookie Exfiltration and Spoofing
CVSS 7.4
CVE-2023-38522 HIGH
Apache Traffic Server <8.1.10, <9.2.4 - SSRF
CVSS 7.5
CVE-2023-50811 MEDIUM
SELESTA Visual Access Manager 4.38.6 - Unauthenticated Access Control Bypass via Parameter Manipulation
CVSS 6.5
CVE-2023-51747 HIGH
Apache James <3.8.1-3.7.5 - SMTP Smuggling
CVSS 7.1
Details
Vulnerabilities 370