← Vulnerability feed

Vulnerability record · CVE-2022-21826 · published 30 September 2022

CVE-2022-21826: Pulse Secure Connect Secure client-side HTTP request smuggling enables XSS

Ivanti · Connect Secure

Pulse Secure 9.115 and below mishandles POST requests by ignoring the Content-Length header and leaving the POST body on the TCP/TLS socket, so that body prefixes the next HTTP request on the same connection. This client-side desync lets an attacker cause a victim's browser to issue a POST to the application, which can lead to cross-site scripting.

5.4 CVSS 3.1 Medium EPSS 45% · top 1.3% CWE-444 · HTTP request smuggling
5.4CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS is medium (5.4) and requires user interaction, but the high EPSS percentile and XSS outcome warrant prompt remediation.

What it is

Pulse Secure 9.115 and below mishandles POST requests by ignoring the Content-Length header and leaving the POST body on the TCP/TLS socket, so that body prefixes the next HTTP request on the same connection. This client-side desync lets an attacker cause a victim's browser to issue a POST to the application, which can lead to cross-site scripting.

Impact

An attacker can induce the victim's browser to send attacker-influenced requests to the application, enabling script execution in the application's origin and possible theft of session data or actions as the victim.

Attack surface

Reached over the network through a victim's browser loading an attacker-controlled page that triggers the desync; the CVSS vector requires low privileges and user interaction, so a victim must visit the malicious content.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at 0.45229 (98.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Pulse Secure / Ivanti Connect Secure above version 9.115 per the vendor advisory.
  • If immediate patching is not possible, restrict or monitor access to the affected web interface and reduce exposure to untrusted web content.
  • Enforce browser-side protections and avoid mixing untrusted sites with the appliance in the same browsing session.
  • Review vendor advisory guidance for any configuration hardening related to the client-side desync issue.

Detection

  • Inspect web/proxy logs for POST requests to the appliance that are followed by unexpected or malformed requests on the same connection.
  • Monitor for anomalous sequences of requests from a single client session that suggest request body carry-over.
  • Look for XSS indicators or unexpected script execution in requests targeting the Pulse Secure web interface.
  • Correlate access logs with known malicious referrers or external sites initiating POSTs to the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-21826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-21826), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.