Illegal HTTP request traffic vulnerability (CL.0) in...
Moderate severity
Unreviewed
Published
Jan 26, 2026
to the GitHub Advisory Database
•
Updated Jan 26, 2026
Description
Published by the National Vulnerability Database
Jan 26, 2026
Published to the GitHub Advisory Database
Jan 26, 2026
Last updated
Jan 26, 2026
Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection using Content-Length headers. This can cause a desynchronization of requests between frontend and backend servers, which could allow request hiding, cache poisoning or security bypass.
References