Vulnerabilities > Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

DATE CVE VULNERABILITY TITLE RISK
2021-11-18 CVE-2021-43669 HTTP Request Smuggling vulnerability in Linuxfoundation Fabric
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0.
network
low complexity
linuxfoundation CWE-444
7.5
2021-11-15 CVE-2021-22959 HTTP Request Smuggling vulnerability in multiple products
The parser in accepts requests with a space (SP) right after the header name before the colon.
network
low complexity
llhttp oracle debian CWE-444
6.5
2021-11-12 CVE-2021-43610 HTTP Request Smuggling vulnerability in Linphone Belle-Sip
Belledonne Belle-sip before 5.0.20 can crash applications such as Linphone via an invalid From header (request URI without a parameter) in an unauthenticated SIP message, a different issue than CVE-2021-33056.
network
low complexity
linphone CWE-444
7.5
2021-11-03 CVE-2021-22960 HTTP Request Smuggling vulnerability in multiple products
The parse function in llhttp < 2.1.4 and < 6.0.6.
network
low complexity
llhttp oracle debian CWE-444
6.5
2021-11-03 CVE-2021-37147 HTTP Request Smuggling vulnerability in multiple products
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests.
network
low complexity
apache debian CWE-444
7.5
2021-11-03 CVE-2021-29991 HTTP Request Smuggling vulnerability in Mozilla Thunderbird
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers.
network
low complexity
mozilla CWE-444
8.1
2021-10-12 CVE-2021-41136 HTTP Request Smuggling vulnerability in multiple products
Puma is a HTTP 1.1 server for Ruby/Rack applications.
network
high complexity
puma debian CWE-444
3.7
2021-09-29 CVE-2021-41732 HTTP Request Smuggling vulnerability in Zeek 4.1.0
An issue was discovered in zeek version 4.1.0.
network
low complexity
zeek CWE-444
7.5
2021-09-24 CVE-2021-31923 HTTP Request Smuggling vulnerability in Pingidentity Pingaccess
Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.
network
low complexity
pingidentity CWE-444
5.3
2021-09-16 CVE-2021-39214 HTTP Request Smuggling vulnerability in Mitmproxy
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy.
network
low complexity
mitmproxy CWE-444
critical
9.8