CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Parent: CWE-436 - Interpretation Conflict

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

371 vulnerabilities with CWE-444
CVE-2023-51747 HIGH
Apache James <3.8.1-3.7.5 - SMTP Smuggling
CVSS 7.1
CVE-2023-52354 HIGH
chasquid < 1.13 - SMTP Smuggling via LF-Terminated Lines
CVSS 7.5
CVE-2023-51701 MEDIUM
fastify/reply-from < 9.6.0 - HTTP Request Smuggling via Malformed Content-Type Header
CVSS 5.3
CVE-2023-49584 MEDIUM
SAP Fiori launchpad - HTTP Request Smuggling via POST on Read-Only Service
CVSS 4.3
CVE-2023-46589 HIGH
Apache Tomcat <11.0.0-M10 - Request Smuggling
CVSS 7.5
CVE-2023-48365 CRITICAL KEV
Qlik Sense Enterprise for Windows - Unauthenticated Remote Code Execution via HTTP Request Tunneling
CVSS 9.6
CVE-2023-46121 MEDIUM
yt-dlp <2023.11.14 - Cookie Exfiltration via Generic Extractor Proxy Injection
CVSS 5.0
CVE-2023-47641 LOW
aiohttp < 3.8.0 - HTTP Request Smuggling via Inconsistent Content-Length and Transfer-Encoding Handling
CVSS 3.4
CVE-2023-47627 MEDIUM
aiohttp < 3.8.6 - HTTP Request Smuggling via Header Parsing
CVSS 5.3
CVE-2023-46846 CRITICAL
Squid 2.6-6.4 - HTTP Request Smuggling via Chunked Decoder Lenience
CVSS 9.3
CVE-2023-46137 MEDIUM
Twisted <23.10.0rc1 - Info Disclosure
CVSS 5.3
CVE-2023-30910 MEDIUM
HPE MSA 1060/2060/2062 Storage Firmware < IN210R004 - HTTP Request Smuggling
CVSS 5.4
CVE-2023-41265 CRITICAL KEV
Qlik Sense Enterprise for Windows <= May 2023 Patch 3 - HTTP Request Tunneling
CVSS 9.6
CVE-2023-40175 HIGH
Puma < 5.6.7 - HTTP Request Smuggling via Chunked Transfer Encoding or Zero-Length Content-Length
CVSS 7.3
CVE-2023-40225 HIGH
HAProxy < 2.0.32, 2.1.x-2.2.30, 2.3.x-2.4.23, 2.5.x-2.6.14, 2.7.x-2.7.9, 2.8.x-2.8.1 - HTTP Request Smuggling
CVSS 7.2
CVE-2023-33934 CRITICAL
Apache Traffic Server <9.2.1 - Info Disclosure
CVSS 9.1
CVE-2023-38697 MEDIUM
socketry/protocol-http1 < 0.15.1 - HTTP Request Smuggling via Malformed Chunk Encoding
CVSS 5.8
CVE-2023-34037 MEDIUM
VMware Horizon Server - HTTP Smuggling
CVSS 5.3
CVE-2023-35944 HIGH
Envoy <1.27.0-1.23.12 - Info Disclosure
CVSS 8.2
CVE-2023-37276 MEDIUM
aiohttp < 3.8.5 - HTTP Request Smuggling via llhttp Parser
CVSS 5.3
CVE-2023-33987 HIGH
SAP Web Dispatcher <7.90 - Unauthenticated RCE
CVSS 8.6
CVE-2023-26137 HIGH
drogon - HTTP Response Splitting via addHeader and addCookie Functions
CVSS 7.2
CVE-2023-33193 CRITICAL
emby.releases < 4.7.0.12 - HTTP Request Smuggling via Header Spoofing
CVSS 9.1
CVE-2023-27238 CRITICAL
LavaLite CMS 9.0.0 - Web Cache Poisoning
CVSS 9.8
CVE-2023-25950 HIGH
HAProxy 2.6.1-2.6.7 and 2.7.0 - HTTP Request Smuggling
CVSS 7.3
Details
Vulnerabilities 371