CVE-2024-10264: Youdao Qanything
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.
Affected products
- Youdao Qanything: version 1.4.1 only
Published 2025-03-20. Last modified 2026-06-17.