← Vulnerability feed

Vulnerability record · CVE-2020-7611 · published 30 March 2020

CVE-2020-7611: Objectcomputing micronaut http request smuggling vulnerability

Objectcomputing · Micronaut

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 22.2% CWE-444 · HTTP request smuggling
9.8CVSS 3.1 base score, v2 7.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-33013Objectcomputing micronaut vulnerabilityMicronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both …EPSS 0.78%7.8CVE-2024-23639Objectcomputing micronaut vulnerabilityMicronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support fo…EPSS 0.26%7.5CVE-2026-33012Objectcomputing micronaut allocation without limits vulnerabilityMicronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through …EPSS 0.75%7.5CVE-2021-32769Objectcomputing micronaut path traversal vulnerabilityMicronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior t…EPSS 1.7%5.3CVE-2022-21700Objectcomputing micronaut uncontrolled resource consumption vulnerabilityMicronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language.…EPSS 1.2%6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed7.5CVE-2025-61884Oracle E-Business Suite Configurator pre-auth data exposure flawOracle Configurator in Oracle E-Business Suite 12.2.3 through 12.2.14 exposes a vulnerability reachable over HTTP without authentication. A successfu…KEVEPSS 96%analysed9.9CVE-2023-48365Qlik Sense Enterprise HTTP Request Smuggling Enables Unauthenticated RCEQlik Sense Enterprise for Windows before August 2023 Patch 2 fails to properly validate HTTP headers, allowing HTTP request tunneling to the backend …KEVEPSS 47%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7611), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.