Skip to main content

CWE archive

CWE-444 CVEs

Programmatic archive

354 CVEs tagged with CWE-44464 Critical, 125 High, 149 Medium, 16 Low, 0 Unrated.

CVE-2025-4366

Published May 22, 2025

A request smuggling vulnerability identified within Pingora’s proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on ca…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23167

Published May 19, 2025

A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling,…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-4600

Published May 16, 2025

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47905

Published May 13, 2025

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRL…

CVSS 5.4 · Medium

CVE-2024-56523

Published May 12, 2025

Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HT…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-43859

Published Apr 24, 2025

h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling…

CVSS 9.1 · Critical

CVE-2024-33452

Published Apr 22, 2025

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29643

Published Apr 18, 2025

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1386

Published Apr 11, 2025

When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such d…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53868

Published Apr 3, 2025

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffic Server: from 9.2.0 through 9.2.9, from 10.0.0 through 10.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31137

Published Apr 1, 2025

React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Rou…

CVSS 7.5 · High

CVE-2024-6827

Published Mar 20, 2025

Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Co…

CVSS 7.5 · High

CVE-2024-10264

Published Mar 20, 2025

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1867

Published Mar 3, 2025

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in ithewei libhv allows HTTP Response Smuggling.This issue affects libhv: through 1.…

CVSS 10.0 · Critical

CVE-2024-56908

Published Feb 13, 2025

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parame…

CVSS 6.8 · Medium

CVE-2025-0752

Published Jan 28, 2025

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to imp…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-29476

Published Dec 14, 2024

In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2…

CVSS 9.1 · Critical

CVE-2024-12397

Published Dec 12, 2024

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a…

CVSS 7.4 · High

CVE-2024-53008

Published Nov 28, 2024

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path…

CVSS 5.3 · Medium

CVE-2024-9666

Published Nov 25, 2024

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is…

CVSS 4.7 · Medium

CVE-2024-52304

Published Nov 18, 2024

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which c…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4639

Published Nov 17, 2024

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a coo…

CVSS 7.4 · High
Showing 101-125 of 354 CVEsPage 5 of 15