İçeriğe atla
Noroxi

CWE-444 · 405 kayıt

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

Bu sınıftaki CVE’ler

405 kayıt

  • SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98

    sap · content server9 Şub 2022

  • An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023

    KritikCVSS 9,9KEVSilahlaştırılmışEPSS %88

    qlik · qlik sense29 Ağu 2023

  • Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.

    KritikCVSS 9,9KEVSilahlaştırılmışEPSS %47

    qlik · qlik sense15 Kas 2023

  • CVE-2023-25690
    64Bu hafta

    Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy

    KritikCVSS 9,8Kavram kanıtıEPSS %85

    apache · http server7 Mar 2023

  • CVE-2025-55315
    59Planlayın

    ASP.NET Security Feature Bypass Vulnerability

    KritikCVSS 9,9Kavram kanıtıEPSS %66

    microsoft · asp.net core14 Eki 2025

  • CVE-2026-48710
    58Planlayın

    Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7

    encode · starlette26 May 2026

  • CVE-2020-9490
    57Planlayın

    Apache HTTP Server versions 2.4.20 to 2.4.43.

    YüksekCVSS 7,5İstismar yokEPSS %89

    apache · http server7 Ağu 2020

  • CVE-2021-30180
    57Planlayın

    Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)

    KritikCVSS 9,8Kavram kanıtıEPSS %60

    apache · dubbo1 Haz 2021

  • CVE-2019-15605
    56Planlayın

    HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

    KritikCVSS 9,8Kavram kanıtıEPSS %57

    nodejs · node.js7 Şub 2020

  • CVE-2022-32214
    51Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re

    OrtaCVSS 6,5İstismar yokEPSS %82

    llhttp · llhttp14 Tem 2022

  • CVE-2022-32215
    47Planlayın

    The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea

    OrtaCVSS 6,5İstismar yokEPSS %69

    llhttp · llhttp14 Tem 2022

  • CVE-2020-11993
    47Planlayın

    Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, loggin

    YüksekCVSS 7,5İstismar yokEPSS %56

    apache · http server7 Ağu 2020

  • CVE-2022-22720
    47Planlayın

    HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

    KritikCVSS 9,8Kavram kanıtıEPSS %28

    apache · http server14 Mar 2022

  • CVE-2017-7658
    45Planlayın

    In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr

    KritikCVSS 9,8İstismar yokEPSS %19

    eclipse · jetty26 Haz 2018

  • CVE-2021-33037
    43Planlayın

    Incorrect Transfer-Encoding handling with HTTP/1.0

    OrtaCVSS 5,3İstismar yokEPSS %75

    apache · tomcat12 Tem 2021

  • CVE-2017-7657
    43Planlayın

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled

    KritikCVSS 9,8İstismar yokEPSS %15

    eclipse · jetty26 Haz 2018

  • CVE-2015-5739
    42Planlayın

    The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers t

    KritikCVSS 9,8İstismar yokEPSS %10

    golang · go18 Eki 2017

  • CVE-2022-29361
    41Planlayın

    Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT

    KritikCVSS 9,8Kavram kanıtıEPSS %8

    palletsprojects · werkzeug24 May 2022

  • CVE-2019-20445
    40Planlayın

    HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr

    KritikCVSS 9,1İstismar yokEPSS %13

    netty · netty29 Oca 2020

  • CVE-2021-45468
    40Planlayın

    Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    imperva · web application firewall14 Oca 2022

  • CVE-2020-10108
    40Planlayın

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %4

    twisted · twisted12 Mar 2020

  • CVE-2015-5740
    40Planlayın

    The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condu

    KritikCVSS 9,8İstismar yokEPSS %4

    golang · go18 Eki 2017

  • CVE-2020-10109
    40Planlayın

    In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %3

    twisted · twisted12 Mar 2020

  • CVE-2019-17559
    40Planlayın

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme pars

    KritikCVSS 9,8İstismar yokEPSS %3

    apache · traffic server23 Mar 2020

  • CVE-2019-17565
    40Planlayın

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked enc

    KritikCVSS 9,8İstismar yokEPSS %3

    apache · traffic server23 Mar 2020

Tüm zafiyet sınıfları