Google Kubernetes Engine
cpe:2.3:a:google:kubernetes_engine:*:*:*:*:*:*:*
- >= 1.25, < 1.25.0-gke.1000
A request smuggling vulnerability has been identified in the Google Cloud Classic Application Load Balancer. This vulnerability arises from improper handling of chunked-encoded HTTP requests, allowing attackers to craft requests that could be misinterpreted by backend servers. The issue has been resolved by disallowing stray data after a chunk, and the vulnerability is no longer exploitable. Classic Application Load Balancer service is not vulnerable after April 26, 2025.
Exploitation of this vulnerability allowed for request smuggling, where crafted HTTP requests could be misinterpreted by backend servers, potentially leading to unauthorized actions or access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.