← Vulnerability feed

Vulnerability record · CVE-2018-21245 · published 15 June 2020

CVE-2018-21245: Apsis pound http request smuggling vulnerability

Apsis · Pound

Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

9.1 CVSS 3.1 Critical EPSS 1.1% · top 35.0% CWE-444 · HTTP request smuggling
9.1CVSS 3.1 base score, v2 6.4
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-21245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10711Debian linux http request smuggling vulnerabilityApsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.EPSS 2.8%7.5CVE-2005-1391Apsis pound vulnerabilityBuffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP head…EPSS 6.1%7.5CVE-2004-2026Apsis pound vulnerabilityFormat string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format st…EPSS 6.6%4.3CVE-2005-3751Apsis pound vulnerabilityHTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, …EPSS 1.5%6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed7.5CVE-2025-61884Oracle E-Business Suite Configurator pre-auth data exposure flawOracle Configurator in Oracle E-Business Suite 12.2.3 through 12.2.14 exposes a vulnerability reachable over HTTP without authentication. A successfu…KEVEPSS 96%analysed9.9CVE-2023-48365Qlik Sense Enterprise HTTP Request Smuggling Enables Unauthenticated RCEQlik Sense Enterprise for Windows before August 2023 Patch 2 fails to properly validate HTTP headers, allowing HTTP request tunneling to the backend …KEVEPSS 47%analysed9.9CVE-2023-41265Qlik Sense Enterprise HTTP request tunneling privilege escalationQlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository applicat…KEVEPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2018-21245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.