Skip to main content

CWE archive

CWE-444 CVEs

Programmatic archive

354 CVEs tagged with CWE-44464 Critical, 125 High, 149 Medium, 16 Low, 0 Unrated.

CVE-2025-69225

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-69224

Published Jan 5, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the p…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12874

Published Dec 19, 2025

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Req…

CVSS 6.3 · Medium

CVE-2023-53878

Published Dec 15, 2025

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsin…

CVSS 6.9 · Medium

CVE-2025-14523

Published Dec 11, 2025

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor th…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-61258

Published Dec 9, 2025

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66373

Published Dec 4, 2025

Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an inva…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-12642

Published Nov 3, 2025

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful expl…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11915

Published Oct 22, 2025

Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in front of impacted models by 2025-09-28. Users do not need to…

CVSS 6.9 · Medium

CVE-2025-61884

Published Oct 12, 2025

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable v…

CVSS 7.5 · High
evidence mentions
17
Buzz score
68.4
Vendor/product tagsBeta · best-effort

CVE-2025-59822

Published Sep 23, 2025

Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper han…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6999

Published Sep 15, 2025

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform…

CVSS 6.9 · Medium

CVE-2025-58056

Published Sep 3, 2025

Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-58068

Published Aug 29, 2025

Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54142

Published Aug 29, 2025

Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connec…

CVSS 4.0 · Medium

CVE-2025-32094

Published Aug 7, 2025

An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "E…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-52892

Published Aug 5, 2025

EspoCRM is a web application with a frontend designed as a single-page application and a REST API backend written in PHP. In versions 9.1.6 and below, if a user loads Espo in the…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53643

Published Jul 14, 2025

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-53628

Published Jul 10, 2025

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to e…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49826

Published Jul 3, 2025

Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49005

Published Jul 3, 2025

Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning v…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6442

Published Jun 25, 2025

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBr…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41235

Published May 30, 2025

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.

CVSS 8.6 · High
Showing 76-100 of 354 CVEsPage 4 of 15