Request Smuggling - Vulnerability

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
December 19, 2025
Last Seen
March 10, 2026

Request Smuggling is a vulnerability tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed December 19, 2025; most recent activity March 10, 2026.

Overview

Request Smuggling is an HTTP-layer vulnerability where crafted requests are interpreted differently by front-end proxies and back-end servers, allowing an attacker to smuggle requests through boundaries and potentially bypass security controls, hijack sessions, or poison caches. The SUSE advisory ties this class of flaw to Netty via CVE-2025-67735, labeling it as a moderate severity issue and highlighting its impact on layered HTTP deployments common in modern web apps.

Related Threat Clusters

Recent Intelligence Reports

  • Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks — Gbhackers · March 10, 2026
  • SUSE: netty Moderate Security Update CVE-2025-67735 Advisory 2025:4489 — Linuxsecurity · December 19, 2025

CVSS v3.1 Breakdown