CWE-444 · 411 записей
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE этого класса
411 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2022-22536Готовый эксплойт | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher sap · content server · CWE-444 | Критическая10,0 | KEV | 97,9 % | 9 февр. 2022 г. |
95Срочно | CVE-2023-41265Готовый эксплойт | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 qlik · qlik sense · CWE-444 | Критическая9,9 | KEV | 88,2 % | 29 авг. 2023 г. |
83Срочно | CVE-2023-48365Готовый эксплойт | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.qlik · qlik sense · CWE-444 | Критическая9,9 | KEV | 47,5 % | 15 нояб. 2023 г. |
64На этой неделе | CVE-2023-25690Proof of concept | Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxyapache · http server · CWE-444 | Критическая9,8 | — | 84,5 % | 7 мар. 2023 г. |
59В плане | CVE-2025-55315Proof of concept | ASP.NET Security Feature Bypass Vulnerabilitymicrosoft · asp.net core · CWE-444 | Критическая9,9 | — | 65,9 % | 14 окт. 2025 г. |
58В плане | CVE-2026-48710Готовый эксплойт | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksencode · starlette · CWE-444 | Средняя6,5 | KEV | 7,1 % | 26 мая 2026 г. |
57В плане | CVE-2020-9490Эксплойта нет | Apache HTTP Server versions 2.4.20 to 2.4.43.apache · http server · CWE-444 | Высокая7,5 | — | 88,8 % | 7 авг. 2020 г. |
57В плане | CVE-2021-30180Proof of concept | Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)apache · dubbo · CWE-444 | Критическая9,8 | — | 60,3 % | 1 июн. 2021 г. |
56В плане | CVE-2019-15605Proof of concept | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformednodejs · node.js · CWE-444 | Критическая9,8 | — | 57,1 % | 7 февр. 2020 г. |
51В плане | CVE-2022-32214Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Средняя6,5 | — | 81,8 % | 14 июл. 2022 г. |
47В плане | CVE-2022-32215Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Средняя6,5 | — | 70,2 % | 14 июл. 2022 г. |
47В плане | CVE-2020-11993Эксплойта нет | Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logginapache · http server · CWE-444 | Высокая7,5 | — | 56,4 % | 7 авг. 2020 г. |
47В плане | CVE-2022-22720Proof of concept | HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlierapache · http server · CWE-444 | Критическая9,8 | — | 28,2 % | 14 мар. 2022 г. |
45В плане | CVE-2017-7658Эксплойта нет | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when preclipse · jetty · CWE-444 | Критическая9,8 | — | 19,4 % | 26 июн. 2018 г. |
43В плане | CVE-2021-33037Эксплойта нет | Incorrect Transfer-Encoding handling with HTTP/1.0apache · tomcat · CWE-444 | Средняя5,3 | — | 74,7 % | 12 июл. 2021 г. |
43В плане | CVE-2017-7657Эксплойта нет | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabledeclipse · jetty · CWE-444 | Критическая9,8 | — | 14,9 % | 26 июн. 2018 г. |
42В плане | CVE-2015-5739Эксплойта нет | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers tgolang · go · CWE-444 | Критическая9,8 | — | 9,6 % | 18 окт. 2017 г. |
41В плане | CVE-2022-29361Proof of concept | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTpalletsprojects · werkzeug · CWE-444 | Критическая9,8 | — | 8,1 % | 24 мая 2022 г. |
40В плане | CVE-2022-32213Эксплойта нет | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding hellhttp · llhttp · CWE-444 | Средняя6,5 | — | 46,0 % | 14 июл. 2022 г. |
40В плане | CVE-2019-20445Эксплойта нет | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Trnetty · netty · CWE-444 | Критическая9,1 | — | 13,5 % | 29 янв. 2020 г. |
40В плане | CVE-2021-45468Proof of concept | Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAimperva · web application firewall · CWE-444 | Критическая9,8 | — | 4,0 % | 14 янв. 2022 г. |
40В плане | CVE-2020-10108Эксплойта нет | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Критическая9,8 | — | 4,0 % | 12 мар. 2020 г. |
40В плане | CVE-2015-5740Эксплойта нет | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condugolang · go · CWE-444 | Критическая9,8 | — | 3,7 % | 18 окт. 2017 г. |
40В плане | CVE-2020-10109Эксплойта нет | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Критическая9,8 | — | 3,3 % | 12 мар. 2020 г. |
40В плане | CVE-2019-17559Эксплойта нет | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsapache · traffic server · CWE-444 | Критическая9,8 | — | 3,2 % | 23 мар. 2020 г. |
- CVE-2022-2253699Срочно
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %sap · content server9 февр. 2022 г.
- CVE-2023-4126595Срочно
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 88 %qlik · qlik sense29 авг. 2023 г.
- CVE-2023-4836583Срочно
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 47 %qlik · qlik sense15 нояб. 2023 г.
- CVE-2023-2569064На этой неделе
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
КритическаяCVSS 9,8Proof of conceptEPSS 85 %apache · http server7 мар. 2023 г.
- CVE-2025-5531559В плане
ASP.NET Security Feature Bypass Vulnerability
КритическаяCVSS 9,9Proof of conceptEPSS 66 %microsoft · asp.net core14 окт. 2025 г.
- CVE-2026-4871058В плане
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %encode · starlette26 мая 2026 г.
- CVE-2020-949057В плане
Apache HTTP Server versions 2.4.20 to 2.4.43.
ВысокаяCVSS 7,5Эксплойта нетEPSS 89 %apache · http server7 авг. 2020 г.
- CVE-2021-3018057В плане
Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)
КритическаяCVSS 9,8Proof of conceptEPSS 60 %apache · dubbo1 июн. 2021 г.
- CVE-2019-1560556В плане
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
КритическаяCVSS 9,8Proof of conceptEPSS 57 %nodejs · node.js7 февр. 2020 г.
- CVE-2022-3221451В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
СредняяCVSS 6,5Эксплойта нетEPSS 82 %llhttp · llhttp14 июл. 2022 г.
- CVE-2022-3221547В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
СредняяCVSS 6,5Эксплойта нетEPSS 70 %llhttp · llhttp14 июл. 2022 г.
- CVE-2020-1199347В плане
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, loggin
ВысокаяCVSS 7,5Эксплойта нетEPSS 56 %apache · http server7 авг. 2020 г.
- CVE-2022-2272047В плане
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
КритическаяCVSS 9,8Proof of conceptEPSS 28 %apache · http server14 мар. 2022 г.
- CVE-2017-765845В плане
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %eclipse · jetty26 июн. 2018 г.
- CVE-2021-3303743В плане
Incorrect Transfer-Encoding handling with HTTP/1.0
СредняяCVSS 5,3Эксплойта нетEPSS 75 %apache · tomcat12 июл. 2021 г.
- CVE-2017-765743В плане
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %eclipse · jetty26 июн. 2018 г.
- CVE-2015-573942В плане
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers t
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %golang · go18 окт. 2017 г.
- CVE-2022-2936141В плане
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT
КритическаяCVSS 9,8Proof of conceptEPSS 8 %palletsprojects · werkzeug24 мая 2022 г.
- CVE-2022-3221340В плане
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he
СредняяCVSS 6,5Эксплойта нетEPSS 46 %llhttp · llhttp14 июл. 2022 г.
- CVE-2019-2044540В плане
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr
КритическаяCVSS 9,1Эксплойта нетEPSS 13 %netty · netty29 янв. 2020 г.
- CVE-2021-4546840В плане
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA
КритическаяCVSS 9,8Proof of conceptEPSS 4 %imperva · web application firewall14 янв. 2022 г.
- CVE-2020-1010840В плане
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %twisted · twisted12 мар. 2020 г.
- CVE-2015-574040В плане
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condu
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %golang · go18 окт. 2017 г.
- CVE-2020-1010940В плане
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %twisted · twisted12 мар. 2020 г.
- CVE-2019-1755940В плане
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme pars
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %apache · traffic server23 мар. 2020 г.