WhisperX tag archive

#HTTP

This page collects WhisperX intelligence signals tagged #HTTP. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-04-01 12:27:18 · GitHub Issues

2. CVE-2026-33870: Netty HTTP Codec Vulnerability Exposes Servers to Request Smuggling Attacks

A critical vulnerability in a widely-used Java networking library opens a direct path for attackers to bypass security controls and poison web caches. Tracked as CVE-2026-33870, the flaw resides in the `io.netty:netty-codec-http` library, specifically version 4.2.9.Final. The core issue is an 'Inconsistent Interpretati...

The Lab · 2026-04-14 15:22:53 · GitHub Issues

3. Tinyproxy 1.11.3 HTTP Request Parsing Desynchronization Vulnerability (CVE-2026-31842)

A critical vulnerability in Tinyproxy, tracked as CVE-2026-31842, exposes the proxy server to HTTP request parsing desynchronization attacks. The flaw stems from a case-sensitive comparison of the Transfer-Encoding header, allowing a remote, unauthenticated attacker to manipulate how the server interprets and forwards ...

The Lab · 2026-04-14 17:22:48 · GitHub Issues

4. Urllib3 Security Patch CVE-2025-50181: Redirect/Retry Mechanism Flaw Exposes Python Apps

A critical security vulnerability in the widely-used Python library urllib3 has been patched, exposing a fundamental flaw in how the library handles HTTP redirects and retries. The vulnerability, tracked as CVE-2025-50181, stems from the library's mechanism for controlling these behaviors through a single `Retry` objec...

The Lab · 2026-04-16 03:22:29 · GitHub Issues

5. CVE-2026-2332: Eclipse Jetty HTTP Parser Vulnerable to Request Smuggling via 'Funky Chunks'

A critical vulnerability in the Eclipse Jetty HTTP/1.1 parser enables request smuggling attacks, allowing attackers to bypass security controls and potentially poison web caches or hijack user sessions. The flaw, designated CVE-2026-2332, stems from improper handling of chunk extensions. Specifically, the parser incorr...