HCL BigFix Service Management HTTP Request Smuggling Vulnerability

Vulnerability

A HTTP request smuggling vulnerability has been identified in HCL BigFix Service Management version 23. This vulnerability arises from inconsistent HTTP request parsing between front-end and back-end servers, allowing attackers to bypass security measures and potentially hijack requests or poison caches.

Impact

Exploitation of this vulnerability could lead to HTTP request smuggling, allowing attackers to manipulate request handling between servers. This could be used to bypass security controls, hijack requests, or poison caches.

Remediation

Users can upgrade to HCL BigFix Service Management version 26 to address this vulnerability.

Added: Apr 21, 2026, 3:47 PM
Updated: Apr 21, 2026, 3:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
6.4
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.