CWE-444: CWE-444

84
Total CVEs
27
Critical
35
High
7.7
Avg CVSS

Yearly Trend

2026
11
2025
22
2024
15
2023
12
2022
14

Top Affected Vendors

1 Apache 8
2 Debian 7
3 Fedoraproject 6
4 Haproxy 3
5 Aiohttp 3
6 Oracle 3
7 Sap 3
8 Mitmproxy 2
9 Tp Link 2
10 Varnish Software 2

All CWE-444 CVEs (84)

CVE-2021-43669
7.5

This vulnerability in HyperLedger Fabric allows attackers to crash orderer nodes by sending specially crafted messages with invalid headers. It affect...

Nov 18, 2021
CVE-2021-41732
7.5

CVE-2021-41732 is an HTTP request splitting vulnerability in Zeek 4.1.0 that allows attackers to manipulate HTTP traffic analysis by injecting malicio...

Sep 29, 2021
CVE-2021-33056
7.5

CVE-2021-33056 is a denial-of-service vulnerability in Belledonne Belle-sip SIP stack where an invalid From header in a SIP message can cause a crash....

Aug 12, 2021
CVE-2021-27577
7.5

Apache Traffic Server incorrectly handles URL fragments, allowing attackers to poison the cache by manipulating fragment identifiers. This affects Apa...

Jun 29, 2021
CVE-2021-31922
7.5

CVE-2021-31922 is an HTTP request smuggling vulnerability in Pulse Secure Virtual Traffic Manager that allows attackers to bypass security controls by...

May 14, 2021
CVE-2024-12397
7.4

A parsing vulnerability in Quarkus-HTTP allows attackers to manipulate cookie values containing specific delimiter characters. This can lead to exfilt...

Dec 12, 2024
CVE-2023-4639
7.4

This vulnerability in Undertow allows attackers to manipulate cookie parsing to exfiltrate HttpOnly cookie values or inject arbitrary cookies. This ca...

Nov 17, 2024
CVE-2023-40175
7.3

This CVE describes an HTTP request smuggling vulnerability in Puma web server that allows attackers to bypass security controls by sending specially c...

Aug 18, 2023
CVE-2023-25950
7.3

This HTTP request smuggling vulnerability in HAProxy allows attackers to manipulate legitimate user requests by exploiting improper request/response h...

Apr 11, 2023
CVE-2022-31081
7.3

CVE-2022-31081 is an HTTP request smuggling vulnerability in HTTP::Daemon Perl library versions before 6.15. It allows attackers to bypass security co...

Jun 27, 2022
CVE-2021-42791
7.3

This vulnerability in VeridiumID VeridiumAD 2.5.3.0 allows any authenticated user to trigger push notifications for any other user and modify the noti...

Jan 28, 2022
CVE-2023-40225
7.2

HAProxy versions through multiple branches forward empty Content-Length headers, violating HTTP standards. This can cause HTTP/1 servers behind HAProx...

Aug 10, 2023
CVE-2025-69224
6.5

CVE-2025-69224 is a request smuggling vulnerability in AIOHTTP's Python HTTP parser that occurs when non-ASCII characters are present in requests. Thi...

Jan 5, 2026
CVE-2024-27982
6.5

This vulnerability in Node.js HTTP server allows HTTP request smuggling when a space precedes the Content-Length header. Attackers can inject a second...

May 7, 2024
CVE-2024-32638
6.3

This CVE describes an HTTP request smuggling vulnerability in Apache APISIX when using the forward-auth plugin. Attackers can exploit inconsistent HTT...

May 2, 2024
CVE-2025-55018
5.8

This HTTP request smuggling vulnerability in Fortinet FortiOS allows unauthenticated attackers to bypass firewall policies by sending specially crafte...

Feb 10, 2026
CVE-2025-30346
5.4

This vulnerability allows attackers to perform client-side desync attacks via HTTP/1 requests against Varnish Cache and Varnish Enterprise. Attackers ...

Mar 21, 2025
CVE-2026-1801
5.3

This HTTP Request Smuggling vulnerability in libsoup allows attackers to send specially crafted chunked requests that get misinterpreted as multiple H...

Feb 3, 2026
CVE-2026-1760
5.3

This HTTP request smuggling vulnerability in SoupServer allows remote attackers to send specially crafted requests that bypass normal request processi...

Feb 2, 2026
CVE-2026-1002
5.3

This vulnerability in Vert.x Web's static handler allows attackers to manipulate the cache to deny access to static files via specially crafted URIs. ...

Jan 15, 2026
CVE-2025-69225
5.3

AIOHTTP versions 3.13.2 and below contain a parser vulnerability that allows non-ASCII decimal characters in HTTP Range headers. This could potentiall...

Jan 6, 2026
CVE-2025-29904
5.3

CVE-2025-29904 is an HTTP request smuggling vulnerability in JetBrains Ktor framework versions before 3.1.1. This allows attackers to bypass security ...

Mar 12, 2025
CVE-2024-9622
5.3

This vulnerability in the resteasy-netty4 library allows HTTP request smuggling attacks using ASCII control characters. When exploited, it causes the ...

Oct 8, 2024
CVE-2025-1386
4.9

This vulnerability in the ch-go library allows an attacker to inject malicious query packets into ClickHouse connections when processing large uncompr...

Apr 11, 2025
CVE-2025-66373
4.8

CVE-2025-66373 is an HTTP request smuggling vulnerability in Akamai Ghost on Akamai CDN edge servers. It allows attackers to hide malicious requests i...

Dec 4, 2025
CVE-2024-9666
4.7

This vulnerability allows attackers to cause denial of service in Keycloak servers by sending malicious proxy headers that trigger expensive DNS resol...

Nov 25, 2024
CVE-2025-52892
4.5

A path traversal vulnerability in EspoCRM versions 9.1.6 and below allows attackers to corrupt the Slim router's cache by accessing URLs with double s...

Aug 5, 2025
CVE-2026-20069
4.3

This vulnerability allows an unauthenticated remote attacker to conduct browser-based attacks (like cross-site scripting) against users of affected Ci...

Mar 4, 2026
CVE-2026-26365
4.0

CVE-2026-26365 is an HTTP request smuggling vulnerability in Akamai Ghost on Akamai CDN edge servers. It allows attackers to send specially crafted HT...

Feb 23, 2026
CVE-2025-54142
4.0

This CVE describes an HTTP request smuggling vulnerability in Akamai Ghost that allows attackers to smuggle requests through an Akamai proxy to backen...

Aug 29, 2025
CVE-2025-32094
4.0

This HTTP request smuggling vulnerability in Akamai Ghost allows attackers to inject a second request within an HTTP/1.x OPTIONS request using obsolet...

Aug 7, 2025
CVE-2025-12811
N/A

This CVE describes an HTTP request smuggling vulnerability in Delinea's Cloud Suite and Privileged Access Service products. Attackers could exploit in...

Feb 18, 2026
CVE-2025-41082
N/A

This vulnerability allows attackers to send malformed HTTP requests that cause desynchronization between frontend and backend servers in Altitude Comm...

Jan 26, 2026
CVE-2023-53878
N/A

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting...

Dec 15, 2025

About CWE-444 (CWE-444)

Our database tracks 84 CVEs classified as CWE-444, with 27 rated critical and 35 rated high severity. The average CVSS score for CWE-444 vulnerabilities is 7.7.

External reference: View CWE-444 on MITRE CWE →

Monitor CWE-444 Vulnerabilities

Get alerted when new CWE-444 CVEs affect your infrastructure.

Start Monitoring Free