CWE-444 HTTP请求的解释不一致性(HTTP请求私运) 类弱点 165 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-444指HTTP请求/响应走私漏洞,属于中间件解释不一致型缺陷。当代理或防火墙与后端服务器对畸形HTTP消息解析逻辑不同时,攻击者可利用此差异构造恶意请求,绕过安全控制或劫持用户会话。开发者应避免使用存在解析歧义的中间件,确保所有HTTP组件采用统一的解析标准,并严格校验请求边界,以消除解释不一致的风险。
POST http://www.website.com/foobar.html HTTP/1.1 Host: www.website.com Connection: Keep-Alive Content-Type: application/x-www-form-urlencoded Content-Length: 0 Content-Length: 54 GET /poison.html HTTP/1.1 Host: www.website.com Bla: GET http://www.website.com/page_to_poison.html HTTP/1.1 Host: www.website.com Connection: Keep-AliveGET /poison.html HTTP/1.1 Host: www.website.com Bla:POST /page.asp HTTP/1.1 Host: www.website.com Connection: Keep-Alive Content-Length: 49223 zzz...zzz ["z" x 49152] POST /page.asp HTTP/1.0 Connection: Keep-Alive Content-Length: 30 POST /page.asp HTTP/1.0 Bla: POST /page.asp?cmd.exe HTTP/1.0 Connection: Keep-Alive| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-40562 | Gazelle Perl 0.49 及以下版本 HTTP 请求 smuggling 漏洞 — Gazelle | - | - | 2026-05-06 |
| CVE-2026-40561 | Perl Starlet 0.31 及之前版本 请求走私漏洞 — Starlet | 7.5AI | HighAI | 2026-05-03 |
| CVE-2026-39805 | Bandit HTTP请求 smuggling漏洞 — bandit | 9.1AI | CriticalAI | 2026-05-01 |
| CVE-2026-40560 | Starman 环境问题漏洞 — Starman | 7.5AI | HighAI | 2026-04-28 |
| CVE-2026-41873 | Apache Pony Mail 环境问题漏洞 — Pony Mail | 9.8AI | CriticalAI | 2026-04-28 |
| CVE-2026-2708 | libsoup 环境问题漏洞 — Red Hat Enterprise Linux 10 | 3.7 | Low | 2026-04-23 |
| CVE-2025-31958 | HCL BigFix Service Management 安全漏洞 — BigFix Service Management (SM) | 3.7 | Low | 2026-04-21 |
| CVE-2026-2332 | Eclipse Jetty 环境问题漏洞 — Eclipse Jetty | 7.4 | High | 2026-04-14 |
| CVE-2026-24880 | Apache Tomcat 环境问题漏洞 — Apache Tomcat | 9.1AI | CriticalAI | 2026-04-09 |
| CVE-2026-31842 | Tinyproxy 安全漏洞 — Tinyproxy | 7.5 | High | 2026-04-07 |
| CVE-2025-65114 | Apache Traffic Server 安全漏洞 — Apache Traffic Server | 7.5AI | HighAI | 2026-04-02 |
| CVE-2026-1491 | IBM多款产品 环境问题漏洞 — Verify Identity Access Container | 5.3 | Medium | 2026-04-01 |
| CVE-2026-2862 | IBM Verify Identity Access Container和IBM Verify Identity Access 环境问题漏洞 — Verify Identity Access Container | 5.3 | Medium | 2026-04-01 |
| CVE-2026-34441 | cpp-httplib 环境问题漏洞 — cpp-httplib | 4.8 | Medium | 2026-03-31 |
| CVE-2026-33870 | Netty 环境问题漏洞 — netty | 7.5 | High | 2026-03-27 |
| CVE-2026-28369 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-28367 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-28368 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-4742 | LiteIDE 安全漏洞 — liteide | 6.5 | - | 2026-03-24 |
| CVE-2026-29057 | Next.js 环境问题漏洞 — next.js | 9.1 | - | 2026-03-18 |
| CVE-2026-23941 | Erlang/OTP 安全漏洞 — OTP | 8.2 | - | 2026-03-13 |
| CVE-2026-1525 | undici 安全漏洞 — undici | 6.5 | Medium | 2026-03-12 |
| CVE-2026-32239 | capnproto 环境问题漏洞 — capnproto | 7.5AI | HighAI | 2026-03-12 |
| CVE-2026-2835 | Pingora 安全漏洞 — https://github.com/cloudflare/pingora | 7.5AI | HighAI | 2026-03-04 |
| CVE-2026-2833 | Pingora 安全漏洞 — https://github.com/cloudflare/pingora | 7.5AI | HighAI | 2026-03-04 |
| CVE-2026-20069 | Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 环境问题漏洞 — Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | 4.3 | Medium | 2026-03-04 |
| CVE-2026-26365 | Akamai Ghost 环境问题漏洞 — Ghost | 4.0 | Medium | 2026-02-23 |
| CVE-2025-12811 | Delinea Cloud Suite 安全漏洞 — Cloud Suite and Privileged Access Service | 8.2AI | HighAI | 2026-02-18 |
| CVE-2025-55018 | Fortinet FortiOS 环境问题漏洞 — FortiOS | 5.2 | Medium | 2026-02-10 |
| CVE-2026-1801 | libsoup 环境问题漏洞 — Red Hat Enterprise Linux 10 | 5.3 | Medium | 2026-02-03 |
CWE-444(HTTP请求的解释不一致性(HTTP请求私运)) 是常见的弱点类别,本平台收录该类弱点关联的 165 条 CVE 漏洞。