CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
371 vulnerabilities with CWE-444
CVE-2023-27493
HIGH
Envoy < 1.22.9 - HTTP Request Smuggling via Unsanitized Request Headers
CVSS 8.1
CVE-2023-27491
MEDIUM
envoyproxy/envoy < 1.22.9 - HTTP Request Smuggling via Malformed Request Lines
CVSS 5.4
CVE-2023-29141
CRITICAL
MediaWiki <1.35.10, <1.36, <1.38.6, <1.39.3 - Info Disclosure
CVSS 9.8
CVE-2023-27522
HIGH
Apache HTTP Server 2.4.30-2.4.55 - HTTP Response Smuggling via mod_proxy_uwsgi Origin Response Header
CVSS 7.5
CVE-2023-25690
CRITICAL
Apache HTTP Server 2.4.0-2.4.55 - HTTP Request Smuggling via mod_proxy RewriteRule
CVSS 9.8
CVE-2023-25725
CRITICAL
HAProxy < 2.0.31 - HTTP Request Smuggling via Empty Header Field Names
CVSS 9.1
CVE-2023-23691
HIGH
Dell PowerVault ME5012, ME5024, and ME5084 Firmware < ME5.1.1.0.5 - Unauthenticated HTTP Request Smuggling
CVSS 8.1
CVE-2022-39163
MEDIUM
IBM Cognos Controller 11.0.0-11.1.0 - Client-Side Desync via HTTP Request Smuggling
CVSS 4.7
CVE-2022-36760
CRITICAL
Apache HTTP Server 2.4.0-2.4.54 - HTTP Request Smuggling via mod_proxy_ajp
CVSS 9.0
CVE-2022-41721
HIGH
Go net/http MaxBytesHandler - HTTP/2 Request Smuggling
CVSS 7.5
CVE-2022-35256
MEDIUM
Node.js 14.0.0-14.13.1, 14.15.0-14.20.0 and llhttp < 6.0.10 - HTTP Request Smuggling via Header Field Parsing
CVSS 6.5
CVE-2022-38114
MEDIUM
SolarWinds Security Event Manager - HTTP Request Smuggling and XSS
CVSS 6.1
CVE-2022-45059
HIGH
Varnish Cache 7.x < 7.1.2 and 7.2.x < 7.2.1 - HTTP Request Smuggling via Hop-by-Hop Header Handling
CVSS 7.5
CVE-2022-42252
HIGH
Apache Tomcat 8.5.0-8.5.82, 9.0.0-M1-9.0.67, 10.0.0-M1-10.0.26, 10.1.0-M1-10.1.0 - HTTP Request Smuggling
CVSS 7.5
CVE-2022-2880
HIGH
Go ReverseProxy - SSRF
CVSS 7.5
CVE-2022-21826
MEDIUM
Ivanti Connect Secure - HTTP Request Smuggling via POST Content-Length Mismanagement
CVSS 5.4
CVE-2022-2466
CRITICAL
Quarkus 2.10.0-2.10.3 - HTTP Request Smuggling via Header Context Mismanagement
CVSS 9.8
CVE-2022-33988
HIGH
dproxy-nexgen - DNS Cache Poisoning via Reused Transaction ID
CVSS 7.5
CVE-2022-1705
MEDIUM
GO < 1.17.12 - HTTP Request Smuggling
CVSS 6.5
CVE-2022-20713
MEDIUM
Cisco Firepower Threat Defense - Cross-Site Scripting via VPN Web Client Services Input Reflection
CVSS 4.3
CVE-2022-25763
HIGH
Apache Traffic Server 8.0.0-9.1.2 - HTTP Request Smuggling via HTTP/2 Request Validation
CVSS 7.5
CVE-2022-31109
HIGH
laminas-diactoros < 2.11.1 - HTTP Request Smuggling via X-Forwarded-* Headers
CVSS 7.2
CVE-2022-32215
MEDIUM
llhttp <14.20.1, <16.17.1, <18.9.1 - HTTP Request Smuggling via Multi-line Transfer-Encoding Header
CVSS 6.5
CVE-2022-32214
MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via CRLF Sequence Mismanagement
CVSS 6.5
CVE-2022-32213
MEDIUM
llhttp < 2.1.5 - HTTP Request Smuggling via Transfer-Encoding Header
CVSS 6.5
Details
Vulnerabilities
371