HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-7122 HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 01 Aug 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Youdao
Youdao qanything
CPEs cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:* cpe:2.3:a:youdao:qanything:1.4.1:*:*:*:*:*:*:*
Vendors & Products Qanything
Qanything qanything
Youdao
Youdao qanything

Thu, 31 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Qanything
Qanything qanything
CPEs cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:*
Vendors & Products Qanything
Qanything qanything
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
Title HTTP Request Smuggling in netease-youdao/qanything
Weaknesses CWE-444
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T18:31:45.800Z

Reserved: 2024-10-22T20:51:59.708Z

Link: CVE-2024-10264

cve-icon Vulnrichment

Updated: 2025-03-20T17:52:28.797Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:15.487

Modified: 2025-08-01T10:51:56.687

Link: CVE-2024-10264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.