CVE-2026-27690
@sap/approuter: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') (CVE-2026-27690)
Description
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
Metrics
Show all metrics
Weakness classes (CWE)
CWE-444Base
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-08 20:22 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:sap:approuter:*:*:*:*:*:node.js:*:* versions up to (excluding) 20.10.0
- Reference Type: SAP SE: https://me.sap.com/notes/3720138 Types: Permissions Required
- Reference Type: SAP SE: https://url.sap/sapsecuritypatchday Types: Vendor Advisory