Description
In Ktor before 1.3.0, request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle \n as a headers separator.
Remediation
References
https://github.com/ktorio/ktor/security/advisories/GHSA-xrr9-rh8p-433v
https://github.com/ktorio/ktor/pull/1547
Related Vulnerabilities
CVE-2016-10534 Vulnerability in npm package electron-packager
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-trino
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa
CVE-2019-10402 Vulnerability in maven package org.jenkins-ci.main:jenkins-core