CWE-444 · 405 kayıt
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Bu sınıftaki CVE’ler
405 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2022-22536Silahlaştırılmış | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher sap · content server · CWE-444 | Kritik10,0 | KEV | %97,9 | 9 Şub 2022 |
95Hemen | CVE-2023-41265Silahlaştırılmış | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 qlik · qlik sense · CWE-444 | Kritik9,9 | KEV | %88,2 | 29 Ağu 2023 |
83Hemen | CVE-2023-48365Silahlaştırılmış | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.qlik · qlik sense · CWE-444 | Kritik9,9 | KEV | %47,5 | 15 Kas 2023 |
64Bu hafta | CVE-2023-25690Kavram kanıtı | Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxyapache · http server · CWE-444 | Kritik9,8 | — | %84,5 | 7 Mar 2023 |
59Planlayın | CVE-2025-55315Kavram kanıtı | ASP.NET Security Feature Bypass Vulnerabilitymicrosoft · asp.net core · CWE-444 | Kritik9,9 | — | %65,9 | 14 Eki 2025 |
58Planlayın | CVE-2026-48710Silahlaştırılmış | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksencode · starlette · CWE-444 | Orta6,5 | KEV | %7,1 | 26 May 2026 |
57Planlayın | CVE-2020-9490İstismar yok | Apache HTTP Server versions 2.4.20 to 2.4.43.apache · http server · CWE-444 | Yüksek7,5 | — | %88,8 | 7 Ağu 2020 |
57Planlayın | CVE-2021-30180Kavram kanıtı | Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)apache · dubbo · CWE-444 | Kritik9,8 | — | %60,3 | 1 Haz 2021 |
56Planlayın | CVE-2019-15605Kavram kanıtı | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformednodejs · node.js · CWE-444 | Kritik9,8 | — | %57,1 | 7 Şub 2020 |
51Planlayın | CVE-2022-32214İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP rellhttp · llhttp · CWE-444 | Orta6,5 | — | %82,5 | 14 Tem 2022 |
47Planlayın | CVE-2022-32215İstismar yok | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding heallhttp · llhttp · CWE-444 | Orta6,5 | — | %68,8 | 14 Tem 2022 |
47Planlayın | CVE-2020-11993İstismar yok | Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logginapache · http server · CWE-444 | Yüksek7,5 | — | %56,4 | 7 Ağu 2020 |
47Planlayın | CVE-2022-22720Kavram kanıtı | HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlierapache · http server · CWE-444 | Kritik9,8 | — | %28,2 | 14 Mar 2022 |
45Planlayın | CVE-2017-7658İstismar yok | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when preclipse · jetty · CWE-444 | Kritik9,8 | — | %19,4 | 26 Haz 2018 |
43Planlayın | CVE-2021-33037İstismar yok | Incorrect Transfer-Encoding handling with HTTP/1.0apache · tomcat · CWE-444 | Orta5,3 | — | %74,7 | 12 Tem 2021 |
43Planlayın | CVE-2017-7657İstismar yok | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabledeclipse · jetty · CWE-444 | Kritik9,8 | — | %14,9 | 26 Haz 2018 |
42Planlayın | CVE-2015-5739İstismar yok | The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers tgolang · go · CWE-444 | Kritik9,8 | — | %9,6 | 18 Eki 2017 |
41Planlayın | CVE-2022-29361Kavram kanıtı | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTpalletsprojects · werkzeug · CWE-444 | Kritik9,8 | — | %8,1 | 24 May 2022 |
40Planlayın | CVE-2019-20445İstismar yok | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Trnetty · netty · CWE-444 | Kritik9,1 | — | %13,5 | 29 Oca 2020 |
40Planlayın | CVE-2021-45468Kavram kanıtı | Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAimperva · web application firewall · CWE-444 | Kritik9,8 | — | %4,0 | 14 Oca 2022 |
40Planlayın | CVE-2020-10108İstismar yok | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Kritik9,8 | — | %4,0 | 12 Mar 2020 |
40Planlayın | CVE-2015-5740İstismar yok | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condugolang · go · CWE-444 | Kritik9,8 | — | %3,7 | 18 Eki 2017 |
40Planlayın | CVE-2020-10109İstismar yok | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Kritik9,8 | — | %3,3 | 12 Mar 2020 |
40Planlayın | CVE-2019-17559İstismar yok | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsapache · traffic server · CWE-444 | Kritik9,8 | — | %3,2 | 23 Mar 2020 |
40Planlayın | CVE-2019-17565İstismar yok | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encapache · traffic server · CWE-444 | Kritik9,8 | — | %3,2 | 23 Mar 2020 |
- CVE-2022-2253699Hemen
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98sap · content server9 Şub 2022
- CVE-2023-4126595Hemen
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %88qlik · qlik sense29 Ağu 2023
- CVE-2023-4836583Hemen
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %47qlik · qlik sense15 Kas 2023
- CVE-2023-2569064Bu hafta
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
KritikCVSS 9,8Kavram kanıtıEPSS %85apache · http server7 Mar 2023
- CVE-2025-5531559Planlayın
ASP.NET Security Feature Bypass Vulnerability
KritikCVSS 9,9Kavram kanıtıEPSS %66microsoft · asp.net core14 Eki 2025
- CVE-2026-4871058Planlayın
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7encode · starlette26 May 2026
- CVE-2020-949057Planlayın
Apache HTTP Server versions 2.4.20 to 2.4.43.
YüksekCVSS 7,5İstismar yokEPSS %89apache · http server7 Ağu 2020
- CVE-2021-3018057Planlayın
Apache Dubbo RCE on customers via Condition route poisoning (Unsafe YAML unmarshaling)
KritikCVSS 9,8Kavram kanıtıEPSS %60apache · dubbo1 Haz 2021
- CVE-2019-1560556Planlayın
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
KritikCVSS 9,8Kavram kanıtıEPSS %57nodejs · node.js7 Şub 2020
- CVE-2022-3221451Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP re
OrtaCVSS 6,5İstismar yokEPSS %82llhttp · llhttp14 Tem 2022
- CVE-2022-3221547Planlayın
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding hea
OrtaCVSS 6,5İstismar yokEPSS %69llhttp · llhttp14 Tem 2022
- CVE-2020-1199347Planlayın
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, loggin
YüksekCVSS 7,5İstismar yokEPSS %56apache · http server7 Ağu 2020
- CVE-2022-2272047Planlayın
HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
KritikCVSS 9,8Kavram kanıtıEPSS %28apache · http server14 Mar 2022
- CVE-2017-765845Planlayın
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr
KritikCVSS 9,8İstismar yokEPSS %19eclipse · jetty26 Haz 2018
- CVE-2021-3303743Planlayın
Incorrect Transfer-Encoding handling with HTTP/1.0
OrtaCVSS 5,3İstismar yokEPSS %75apache · tomcat12 Tem 2021
- CVE-2017-765743Planlayın
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled
KritikCVSS 9,8İstismar yokEPSS %15eclipse · jetty26 Haz 2018
- CVE-2015-573942Planlayın
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers t
KritikCVSS 9,8İstismar yokEPSS %10golang · go18 Eki 2017
- CVE-2022-2936141Planlayın
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HT
KritikCVSS 9,8Kavram kanıtıEPSS %8palletsprojects · werkzeug24 May 2022
- CVE-2019-2044540Planlayın
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Tr
KritikCVSS 9,1İstismar yokEPSS %13netty · netty29 Oca 2020
- CVE-2021-4546840Planlayın
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WA
KritikCVSS 9,8Kavram kanıtıEPSS %4imperva · web application firewall14 Oca 2022
- CVE-2020-1010840Planlayın
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
KritikCVSS 9,8İstismar yokEPSS %4twisted · twisted12 Mar 2020
- CVE-2015-574040Planlayın
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to condu
KritikCVSS 9,8İstismar yokEPSS %4golang · go18 Eki 2017
- CVE-2020-1010940Planlayın
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
KritikCVSS 9,8İstismar yokEPSS %3twisted · twisted12 Mar 2020
- CVE-2019-1755940Planlayın
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme pars
KritikCVSS 9,8İstismar yokEPSS %3apache · traffic server23 Mar 2020
- CVE-2019-1756540Planlayın
There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked enc
KritikCVSS 9,8İstismar yokEPSS %3apache · traffic server23 Mar 2020