Перейти к содержимому
Noroxi

CWE-444 · 411 записей

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CVE этого класса

411 записей

  • CVE-2022-22536
    99Срочно

    SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %

    sap · content server9 февр. 2022 г.

  • CVE-2023-41265
    95Срочно

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023

    КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 88 %

    qlik · qlik sense29 авг. 2023 г.

  • CVE-2023-48365
    83Срочно

    Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.

    КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 47 %

    qlik · qlik sense15 нояб. 2023 г.

  • CVE-2023-25690
    64На этой неделе

    Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

    КритическаяCVSS 9,8Proof of conceptEPSS 85 %

    apache · http server7 мар. 2023 г.

  • CVE-2025-55315
    59В плане

    ASP.NET Security Feature Bypass Vulnerability

    КритическаяCVSS 9,9Proof of conceptEPSS 66 %

    microsoft · asp.net core14 окт. 2025 г.

  • CVE-2026-48710
    58В плане

    Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

    СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %

    encode · starlette26 мая 2026 г.

  • CVE-2020-9490
    57В плане

    Apache HTTP Server versions 2.4.20 to 2.4.43.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 89 %

    apache · http server7 авг. 2020 г.

  • CVE-2021-30180
    57В плане

    Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)

    КритическаяCVSS 9,8Proof of conceptEPSS 60 %

    apache · dubbo1 июн. 2021 г.

  • CVE-2019-15605
    56В плане

    HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

    КритическаяCVSS 9,8Proof of conceptEPSS 57 %

    nodejs · node.js7 февр. 2020 г.

  • CVE-2022-32214
    51В плане

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    СредняяCVSS 6,5Эксплойта нетEPSS 82 %

    llhttp · llhttp14 июл. 2022 г.

  • CVE-2022-32215
    47В плане

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    СредняяCVSS 6,5Эксплойта нетEPSS 70 %

    llhttp · llhttp14 июл. 2022 г.

  • CVE-2020-11993
    47В плане

    Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, loggin

    ВысокаяCVSS 7,5Эксплойта нетEPSS 56 %

    apache · http server7 авг. 2020 г.

  • CVE-2022-22720
    47В плане

    HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

    КритическаяCVSS 9,8Proof of conceptEPSS 28 %

    apache · http server14 мар. 2022 г.

  • CVE-2017-7658
    45В плане

    In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr

    КритическаяCVSS 9,8Эксплойта нетEPSS 19 %

    eclipse · jetty26 июн. 2018 г.

  • CVE-2021-33037
    43В плане

    Incorrect Transfer-Encoding handling with HTTP/1.0

    СредняяCVSS 5,3Эксплойта нетEPSS 75 %

    apache · tomcat12 июл. 2021 г.

  • CVE-2017-7657
    43В плане

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled

    КритическаяCVSS 9,8Эксплойта нетEPSS 15 %

    eclipse · jetty26 июн. 2018 г.

  • CVE-2015-5739
    42В плане

    The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers t

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    golang · go18 окт. 2017 г.

  • CVE-2022-29361
    41В плане

    Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT

    КритическаяCVSS 9,8Proof of conceptEPSS 8 %

    palletsprojects · werkzeug24 мая 2022 г.

  • CVE-2022-32213
    40В плане

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding he

    СредняяCVSS 6,5Эксплойта нетEPSS 46 %

    llhttp · llhttp14 июл. 2022 г.

  • CVE-2019-20445
    40В плане

    HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr

    КритическаяCVSS 9,1Эксплойта нетEPSS 13 %

    netty · netty29 янв. 2020 г.

  • CVE-2021-45468
    40В плане

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    imperva · web application firewall14 янв. 2022 г.

  • CVE-2020-10108
    40В плане

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    twisted · twisted12 мар. 2020 г.

  • CVE-2015-5740
    40В плане

    The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condu

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    golang · go18 окт. 2017 г.

  • CVE-2020-10109
    40В плане

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    twisted · twisted12 мар. 2020 г.

  • CVE-2019-17559
    40В плане

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme pars

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    apache · traffic server23 мар. 2020 г.

Все классы уязвимостей