http
32 articles with this tag
LOW
LOW
INFO
MEDIUM
HIGH
INFO
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
INFO
MEDIUM
MEDIUM
HIGH
LOW
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
INFO
CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects
Friday Squid Blogging: “Squidbleed” Vulnerability
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
USN-8516-1: Apache HTTP Server vulnerabilities
Hitachi Energy PROMOD V
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection
29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
RHSA-2026:25090: Important: httpd:2.4 security update
CVE-2025-60876 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
CVE-2026-6324 Libsoup: libsoup: http request smuggling via unsigned to signed conversion error
CVE-2025-23167 A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.
This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests.
The issue was resolved by upgrading `llhttp` to version 9, which enforces correct header termination.
Impact:
* This vulnerability affects only Node.js 20.x users prior to the `llhttp` v9 upgrade.
USN-8343-1: multipart vulnerability
USN-8338-1: Apache HTTP Server vulnerabilities
CVE-2026-9256 NGINX ngx_http_rewrite_module vulnerability
CVE-2026-44431 urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
RHSA-2026:15968: Moderate: libsoup3 security update
CVE-2026-2708 Libsoup: libsoup: http request smuggling via duplicate content-length headers
CVE-2026-1965 bad reuse of HTTP Negotiate connection
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
CVE-2026-40175 Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE-2025-62718 Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF
CVE-2026-3644 Incomplete control character validation in http.cookies
HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)
Cisco Secure Web Appliance Authentication Bypass Vulnerability
Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Fixing request smuggling vulnerabilities in Pingora OSS deployments
The Forgotten Bug: How a Node.js Core Design Flaw Enables HTTP Request Splitting
Http11Probe - Probe for Http 1.1 compliance