What is CWE-444?
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
HTTP requests or responses ("messages") can be malformed or unexpected in ways that cause web servers or clients to interpret the messages in different ways than intermediary HTTP agents such as load balancers, reverse proxies, web caching proxies, application firewalls, etc. For example, an adversary may be able to add duplicate or different header fields that a client or server might interpret as one set of messages, whereas the intermediary might interpret the same sequence of bytes as a different set of messages. For example, discrepancies can arise in how to handle duplicate headers like two Transfer-encoding (TE) or two Content-length (CL), or the malicious HTTP message will have different headers for TE and CL. The inconsistent parsing and interpretation of messages can allow the adversary to "smuggle" a message to the client/server without the intermediary being aware of it. This weakness is usually the result of the usage of outdated or incompatible HTTP protocol versions in the HTTP agents.
CWE-444 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Web Based; Web Server.
Source: MITRE CWE (CWE-444 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Non-Repudiation, Access Control — Unexpected State, Hide Activities, Bypass Protection Mechanism. An attacker could create HTTP messages to exploit a number of weaknesses including 1) the message can trick the web server to associate a URL with another URL's webpage and caching the contents of the webpage (web cache poisoning attack), 2) the message can be structured to bypass the firewall protection mechanisms and gain unauthorized access to a web application, and 3) the message can invoke a script or a page that returns client credentials (similar to a Cross Site Scripting attack).
Source: MITRE CWE, common consequences.
How CWE-444 is exploited in the wild
Threadlinqs maps 8 CVEs to CWE-444, published between 2025-10-12 and 2026-09-27. 1 is listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 1 is tied to ransomware campaigns. By CVSS v3 severity the set splits into 1 critical, 2 high, 2 medium. The highest EPSS score in the set is 97.5% (CVE-2025-61884), the modelled probability of exploitation in the next 30 days. 17 tracked threats reference CWE-444 directly or through a CVE it covers; the most recent is “Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC” (2026-10-04). Affected products concentrate in Citrix NetScaler (1), IBM (1), Kludex (1), among 7 vendors in total.
Vulnerabilities (CVEs)
All 8 CVEs mapped to CWE-444, CISA KEV first, then by CVSS score.
- CVE-2025-61884 — CISA KEV · CVSS 7.5 high · EPSS 97.5% · published 2025-10-12
- CVE-2026-27690 — CVSS 9.1 critical · published 2026-07-14
- CVE-2026-8646 — CVSS 7.4 high · EPSS 0.3% · published 2026-06-22
- CVE-2026-48710 — CVSS 6.5 medium · EPSS 0.0% · published 2026-05-26
- CVE-2026-71554 — CVSS 5.3 medium · published 2026-08-06
- CVE-2026-82672 — EPSS 0.3% · published 2026-09-19
- CVE-2026-75922 — EPSS 0.2% · published 2026-08-23
- CVE-2026-88773 — published 2026-09-27
Affected vendors
- Citrix NetScaler — 1 CVE
- IBM — 1 CVE
- Kludex — 1 CVE
- Oracle Corporation — 1 CVE
- SAP_SE — 1 CVE
- elixir-mint — 1 CVE
- python-hyper — 1 CVE
Threat activity
17 tracked threats cite CWE-444:
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARCMEDIUM
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027CRITICAL
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)CRITICAL
- Qilin-Linked Campaign Exploits MCP Gateway and LLM Framework Flaws (CVE-2026-59822, CVE-2026-42271, CVE-2026-48710) for RCE and CryptominingCRITICAL
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day (CVE-2026-63078)HIGH
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)HIGH
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch ReleasedCRITICAL
- CVE-2026-44747: Critical Memory Corruption in SAP NetWeaver Application Server ABAP (CVSS 9.9)CRITICAL
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)CRITICAL
- SAP July 2026 Patch Day: Critical Memory Corruption in NetWeaver ABAP (CVE-2026-44747, CVSS 9.9) Among 16 Security NotesCRITICAL
- SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw (CVE-2026-44747), Plus Critical Approuter and Commerce Cloud BugsCRITICAL
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoCCRITICAL
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass ExploitationCRITICAL
- CVE-2026-42271: LiteLLM AI Gateway OS Command Injection via MCP Test Endpoints, Chained to Unauthenticated RCE with CVE-2026-48710 (CISA KEV, Active Exploitation)CRITICAL
- CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCECRITICAL
- IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)CRITICAL
- BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)CRITICAL
Mitigations
- Implementation: Use a web server that employs a strict HTTP parsing procedure, such as Apache [REF-433].
- Implementation: Use only SSL communication.
- Implementation: Terminate the client session after each request.
- System Configuration: Turn all pages to non-cacheable.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.