CWE-444

CWE-444 · 11 records · 8 with a public proof-of-concept

Records the NVD classes under CWE-444, highest CVSS first.

  1. CRITICAL 10CVE-2026-88773

    Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 a…

    netscaler application delivery controller · netscaler gateway

    AI risk analysis on Exploit-DB.ai →

  2. CRITICAL 9.8CVE-2026-37604public PoC

    pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trusted proxy. Because the …

    AI risk analysis on Exploit-DB.ai →

  3. CRITICAL 9.1CVE-2026-86350

    Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-73548public PoC

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade. An unauthenticated HTT…

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.3CVE-2026-100666public PoC

    Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request by calling pollMethod() once per response, including for 1xx…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-100659public PoC

    Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host header field, when both present, carry the same value. A remote …

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 6.5CVE-2026-85078public PoC

    Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticat…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 5.4CVE-2026-100724public PoC

    http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header by default in reverseProxy() and reverseProxyRouting() when dispatching to configured virtual hosts. If these functions a…

    AI risk analysis on Exploit-DB.ai →

  9. LOW 3.7CVE-2026-77756

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request from another user to fail when …

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-94194public PoC

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize an intermediary and the Mint client on a pooled connection, poisoning the responses to subseque…

    AI risk analysis on Exploit-DB.ai →

  11. UNSCOREDCVE-2026-82672public PoC

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabling response-queue poiso…

    AI risk analysis on Exploit-DB.ai →