PT-2026-4738 · Unknown · Altitude Communication Server

Published

2026-01-26

·

Updated

2026-01-26

·

CVE-2025-41082

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Altitude Communication Server (affected versions not specified)
Description An issue exists in Altitude Communication Server related to the handling of HTTP requests. Inconsistent analysis of multiple HTTP requests over a single Keep-Alive connection, specifically utilizing Content-Length headers, can lead to a desynchronization between frontend and backend servers. This desynchronization may allow for request hiding, cache poisoning, or security bypass.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

CVE-2025-41082

Affected Products

Altitude Communication Server