Inconsistent interpretation of HTTP requests in mitmproxy - CVE-2022-24766
Published: March 19, 2022 / Updated: April 13, 2026
mitmproxy
mitmproxy.org
Description
The vulnerability allows a remote attacker to bypass security checks.
The vulnerability exists due to insufficient protection against HTTP request smuggling in the HTTP/1 message handling logic when processing crafted HTTP requests and responses through the proxy. A remote attacker can smuggle a request or response through the proxy to bypass security checks.
This issue affects deployments where the proxy is used to protect an HTTP/1 service.