CVE-2024-10264

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
References
Link Resource
https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*

History

01 Aug 2025, 10:51

Type Values Removed Values Added
CPE cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:* cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*
First Time Youdao
Youdao qanything

31 Jul 2025, 15:48

Type Values Removed Values Added
CPE cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:*
References () https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 - () https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02 - Exploit, Third Party Advisory
Summary
  • (es) La vulnerabilidad de contrabando de solicitudes HTTP en netease-youdao/qanything versión 1.4.1 permite a los atacantes explotar inconsistencias en la interpretación de las solicitudes HTTP entre un proxy y un servidor. Esto puede provocar acceso no autorizado, eludir los controles de seguridad, secuestro de sesiones, fuga de datos y, potencialmente, la ejecución de código arbitrario.
First Time Qanything qanything
Qanything
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.8

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-08-01 10:51


NVD link : CVE-2024-10264

Mitre link : CVE-2024-10264

CVE.ORG link : CVE-2024-10264


JSON object : View

Products Affected

youdao

  • qanything
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')