CVE-2024-10264: Youdao Qanything

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.

Affected products

  • Youdao Qanything: version 1.4.1 only

Published 2025-03-20. Last modified 2026-06-17.