Impact
ServiceTalk HTTP/1.x incorrectly processes malformed Transfer-Encoding headers, allowing an attacker to manipulate the framing of HTTP requests and cause downstream services to interpret them differently. The primary impact is that request smuggling could lead to unintended request handling.
Affected Systems
Apple ServiceTalk, all released versions prior to 0.42.65 are vulnerable. The advisory notes that version 0.42.65 contains the fix.
Risk and Exploitability
The likely attack vector is over the network via crafted HTTP requests that contain malformed Transfer-Encoding headers. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 7.5, reflecting a high severity of request smuggling that can compromise the integrity and availability of downstream services. The flaw indicates an attacker could send malformed requests to manipulate downstream behavior, aligning with CWE-444.
OpenCVE Enrichment