CWE-444 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-444 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2022-22536SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Con…97.9%심각10.0● 랜섬웨어 캠페인에 사용됨CVE-2025-61884Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI).…95.9%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2023-41265An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May …88.2%심각9.9● 랜섬웨어 캠페인에 사용됨CVE-2023-48365Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code exec…47.5%심각9.9● 실제 악용이 확인됨CVE-2026-48710Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request h…7.1%보통6.5CVE-2026-93574A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulne…0.9%보통6.5CVE-2026-93569A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's …0.7%높음8.2CVE-2026-37604pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _pro…0.7%심각9.8
전체 목록
44건
CVE-2026-93573A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-…0.6%보통6.5
CVE-2026-82672Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint …0.5%보통6.3
CVE-2026-69217Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts…0.5%높음8.7
CVE-2026-73548Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.…0.5%높음7.5
CVE-2026-69205Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a ca…0.4%높음8.7
CVE-2026-73494blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and…0.4%높음7.4
CVE-2023-54397Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Lengt…0.4%심각9.0
CVE-2024-14029Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no mess…0.4%심각9.0
CVE-2026-88773Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetSc…0.4%심각9.3
CVE-2026-88008Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik…0.3%높음7.0
CVE-2026-69204Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject …0.3%심각9.2
CVE-2026-100724http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains)…0.3%보통6.3
CVE-2026-81356Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows …0.3%높음8.2
CVE-2026-94194Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint …0.3%보통6.3
CVE-2026-85078Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body han…0.3%보통6.5
CVE-2026-63718Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerabil…0.3%높음7.5
CVE-2026-86350Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tom…0.3%심각9.1
CVE-2026-19203A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an inter…0.3%높음8.3
CVE-2026-79713The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in…0.3%보통6.5
CVE-2026-88009Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts …0.3%높음8.8
CVE-2026-15634IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to…0.3%보통6.5
CVE-2026-15396IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to…0.3%보통6.5
CVE-2026-89044Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly vali…0.2%보통6.9
CVE-2026-77756Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomca…0.3%낮음3.7
CVE-2026-69216Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the…0.2%보통5.4
CVE-2026-103399A flaw was found in SoupServer (libsoup). When an HTTP/1.x client sends a request with Expect: 100-continue an…0.2%보통5.3
CVE-2026-100666Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versio…0.2%보통6.9
CVE-2026-100659Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforc…0.2%보통6.9
CVE-2026-11710IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper ha…0.2%보통6.5
CVE-2026-18540undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an e…0.2%낮음3.7
CVE-2026-11722IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smug…0.2%보통4.8
CVE-2026-11548IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smug…0.2%보통4.8
CVE-2026-10841IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.0.2%보통4.2
CVE-2018-3908An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings …높음7.5
CVE-2018-3909An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings …높음8.6
CVE-2018-3907An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings …심각10.0
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.