VulnSea

CWE-444

CVEs classified under CWE-444, newest first.

98 CVEsRSS

CVE-2026-73548High· 7.5
yesterday

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade.…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-82672Medium· 6.3PoC
3d ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

Twilightelixir-mint · mintEPSS 0.30%via NVD
CVE-2026-93574Medium· 6.5
4d ago

A flaw was found in Netty's `netty-codec-http` component

A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chun…

SunlitRed Hat · netty-codec-httpEPSS 0.36%via NVD
CVE-2026-11548Medium· 4.8
4d ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-11710Medium· 6.5
4d ago

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

SunlitIBM · WebSphere Application ServerEPSS 0.28%via NVD
CVE-2026-11722Medium· 4.8
4d ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-10841Medium· 4.2
4d ago

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.

SunlitIBM · CICS TX AdvancedEPSS 0.21%via NVD
CVE-2026-93573Medium· 6.5
4d ago

A flaw was found in Netty's HTTP/1.1 decoder

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing …

SunlitRed Hat · netty-codec-httpEPSS 0.23%via NVD
CVE-2026-93569High· 8.2
4d ago

A flaw was found in Netty

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, …

TwilightRed Hat · netty-codec-http2EPSS 0.37%via NVD
CVE-2026-79713Medium· 6.5
4d ago

The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered u…

The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered u…

SunlitEPSS 0.21%via NVD
CVE-2026-85078Medium· 6.5
5d ago

Sanic is an opensource python web server/framework

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer.…

Sunlitsanic-org · sanicEPSS 0.30%via NVD
CVE-2026-69217High· 8.7
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing duplicate Content-Length headers and uses the last value instead of rejecting the message. When an Ember server is b…

Twilighthttp4s · http4sEPSS 0.50%via NVD
CVE-2026-69205High· 8.7
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitive substring test for the Transfer-Encoding value and decodes header bytes with the platform default charset. Values …

Twilighthttp4s · org.http4s:http4s-ember-core_3EPSS 0.40%via NVD
CVE-2026-69216Medium· 5.4
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the r…

Sunlithttp4s · http4sEPSS 0.24%via NVD
CVE-2026-69204Critical· 9.2
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing r…

Midnighthttp4s · http4sEPSS 0.33%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
1w ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2023-54397High· 7.5
1w ago

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy val…

Twilighttornadoweb · tornadoEPSS 0.37%via NVD
CVE-2026-15634Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-15396Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-73494High· 7.4
1w ago

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org…

Twilighthttp4s · blazeEPSS 0.37%via NVD
CVE-2026-90678High· 7.5
1w ago

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5

An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic…

TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.52%via NVD
CVE-2026-88009High· 8.2
1w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…

Twilighttraefik · traefikEPSS 0.27%via NVD
CVE-2026-89044Medium· 6.5
1w ago

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Sunlitnetty · nettyEPSS 0.24%via NVD
CVE-2026-88008Critical· 9.1⚖ disputed
1w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

Midnighttraefik · traefikEPSS 0.34%via NVD
CVE-2026-68006Critical· 9.1
1w ago

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

MidnightEPSS 0.37%via NVD
CVE-2026-88879High· 8.2⚖ disputed
1w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three disti…

Twilighttraefik · traefikEPSS 0.21%via NVD
CVE-2026-81356High· 8.2
2w ago

Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Twilightmicrosoft · visual_studio_codeEPSS 0.32%via NVD
CVE-2026-19203High· 8.3
2w ago

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused by…

TwilightEclipse Foundation · Eclipse JettyEPSS 0.29%via NVD
CVE-2026-85008Low· 3.7
2w ago

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is n…

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is n…

Sunlitnodejs · undiciEPSS 0.12%via NVD
CVE-2026-18540Low· 3.7
2w ago

undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers

undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server…

Sunlitnodejs · undiciEPSS 0.24%via NVD
CWE-444 vulnerabilities (CVEs) · VulnSea