CVE-2026-27690

@sap/approuter: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') (CVE-2026-27690)

criticalEPSS 0.7%

Description

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

npm@sap/approuter

Metrics

9.1
Source: nvd-v3
51.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-14 03:31 UTC
CWE-444

Weakness classes (CWE)

  • CWE-444Base

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

    The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-09-08 20:22 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:* versions up to (excluding) 20.10.0
    • Reference Type: SAP SE: https://me.sap.com/notes/3720138 Types: Permissions Required
    • Reference Type: SAP SE: https://url.sap/sapsecuritypatchday Types: Vendor Advisory

Linked advisories