CWE-444: HTTP Request/Response Smuggling
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
254 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-48710 — Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
- CVE-2025-1867 — HTTP Response Smuggling Vulnerability in libhv
- CVE-2024-41110 — Moby authz zero length regression
- CVE-2024-27922 — HTTP Handling Vulnerability in the Bare server
- CVE-2026-28497 — TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling)
- CVE-2026-2835 — HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing
- CVE-2026-2833 — HTTP Request Smuggling via Premature Upgrade
- CVE-2025-43859 — h11 accepts some malformed Chunked-Encoding bodies
- CVE-2024-49768 — Waitress has request processing race condition in HTTP pipelining with invalid first request
- CVE-2024-23316 — PingAccess HTTP Request Desynchronization Weakness
- CVE-2026-24880 — Apache Tomcat: Request smuggling via invalid chunk extension
- CVE-2025-4600 — HTTP Request Smuggling in Google Cloud Classic Application Load Balancer due to Improper Chunked Encoding Validation
- CVE-2024-41671 — twisted.web has disordered HTTP pipeline response
- CVE-2026-45372 — cpp-httplib: HTTP header value percent-decoding in server-side `parse_header` enables CRLF injection
- CVE-2026-41873 — Pony Mail: Admin account takeover via request smuggling
- CVE-2026-54388 — Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers
- CVE-2026-54387 — Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization
- CVE-2026-48746 — vLLM: OpenAI auth bypass
- CVE-2026-63385 — Libevent: HTTP header handling bugs create risk of access control bypass.
- CVE-2026-63382 — libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling
Recently published
- CVE-2026-19203 — A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary pr
- CVE-2026-18540 — undici vulnerable to downstream response splitting via retry interceptor
- CVE-2026-84380 — HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
- CVE-2026-84363 — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
- CVE-2026-78605 — Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure
- CVE-2026-73812 — inets, httpd: HTTP Request Smuggling via Transfer-Encoding and Content-Length
- CVE-2026-73276 — inets, httpd: HTTP Request Smuggling via Whitespace-Before-Colon Header Dropping i
- CVE-2026-66357 — inets,httpd:HTTP Request Smuggling via obs-fold Header Continuation
- CVE-2026-48932 — A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou
- CVE-2026-74848 — Apache APISIX: Cross-user response poisoning in serverless plugins
- CVE-2026-75922 — Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line
- CVE-2026-63385 — Libevent: HTTP header handling bugs create risk of access control bypass.
- CVE-2026-63379 — Libevent: HTTP Header smuggling
- CVE-2026-63382 — libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling
- CVE-2026-73256 — Mongoose: HTTP/1.0 detection off-by-one enables request smuggling via chunked TE
- CVE-2026-73257 — Mongoose: Content-Length + Transfer-Encoding coexistence enables request smuggling
- CVE-2026-55087 — Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)
- CVE-2026-73051 — actix-http before 3.12.1 HTTP Request Smuggling via CL.TE
- CVE-2026-73495 — blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
- CVE-2026-14180 — Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap