CVE-2024-10264

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
References
Link Resource
https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*

History

01 Aug 2025, 10:51

Type Values Removed Values Added
CPE cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:* cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*
First Time Youdao qanything
Youdao

31 Jul 2025, 15:48

Type Values Removed Values Added
References () https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 - () https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 - Exploit, Third Party Advisory
CPE cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8
Summary
  • (es) La vulnerabilidad de contrabando de solicitudes HTTP en netease-youdao/qanything versión 1.4.1 permite a los atacantes explotar inconsistencias en la interpretación de las solicitudes HTTP entre un proxy y un servidor. Esto puede provocar acceso no autorizado, eludir los controles de seguridad, secuestro de sesiones, fuga de datos y, potencialmente, la ejecución de código arbitrario.
First Time Qanything
Qanything qanything

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 10:51


NVD link : CVE-2024-10264

Mitre link : CVE-2024-10264

CVE.ORG link : CVE-2024-10264


JSON object : View

Products Affected

youdao

  • qanything
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')