Vulnerability record · CVE-2022-21826 · published 30 September 2022
CVE-2022-21826: Pulse Secure Connect Secure client-side HTTP request smuggling enables XSS
Ivanti · Connect Secure
Pulse Secure 9.115 and below mishandles POST requests by ignoring the Content-Length header and leaving the POST body on the TCP/TLS socket, so that body prefixes the next HTTP request on the same connection. This client-side desync lets an attacker cause a victim's browser to issue a POST to the application, which can lead to cross-site scripting.
Description
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS is medium (5.4) and requires user interaction, but the high EPSS percentile and XSS outcome warrant prompt remediation.
What it is
Pulse Secure 9.115 and below mishandles POST requests by ignoring the Content-Length header and leaving the POST body on the TCP/TLS socket, so that body prefixes the next HTTP request on the same connection. This client-side desync lets an attacker cause a victim's browser to issue a POST to the application, which can lead to cross-site scripting.
Impact
An attacker can induce the victim's browser to send attacker-influenced requests to the application, enabling script execution in the application's origin and possible theft of session data or actions as the victim.
Attack surface
Reached over the network through a victim's browser loading an attacker-controlled page that triggers the desync; the CVSS vector requires low privileges and user interaction, so a victim must visit the malicious content.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.45229 (98.7th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Pulse Secure / Ivanti Connect Secure above version 9.115 per the vendor advisory.
- If immediate patching is not possible, restrict or monitor access to the affected web interface and reduce exposure to untrusted web content.
- Enforce browser-side protections and avoid mixing untrusted sites with the appliance in the same browsing session.
- Review vendor advisory guidance for any configuration hardening related to the client-side desync issue.
Detection
- Inspect web/proxy logs for POST requests to the appliance that are followed by unexpected or malformed requests on the same connection.
- Monitor for anomalous sequences of requests from a single client session that suggest request body carry-over.
- Look for XSS indicators or unexpected script execution in requests targeting the Pulse Secure web interface.
- Correlate access logs with known malicious referrers or external sites initiating POSTs to the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-21826 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-21826), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.