HTTP Request Smuggling in akka-http-core
Moderate severity
GitHub Reviewed
Published
May 10, 2021
to the GitHub Advisory Database
•
Updated Feb 21, 2023
Package
Affected versions
>= 10.2.0, < 10.2.4
< 10.1.14
Patched versions
10.2.4
10.1.14
Description
Published by the National Vulnerability Database
Feb 17, 2021
Reviewed
Mar 19, 2021
Published to the GitHub Advisory Database
May 10, 2021
Last updated
Feb 21, 2023
A vulnerable Akka HTTP server will accept a malformed message and hand it over to the user. If the user application proxies this message to another server unchanged and that server also accepts that message but interprets it as two HTTP messages, the second message has reached the second server without having been inspected by the proxy.
References