Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67vw-jjgw-xcvq

Опубликовано: 26 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request hiding, cache poisoning or security bypass.

Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request hiding, cache poisoning or security bypass.

EPSS

Процентиль: 2%
0.00014
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-444

Связанные уязвимости

nvd
13 дней назад

Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request hiding, cache poisoning or security bypass.

EPSS

Процентиль: 2%
0.00014
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-444