HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HT…

cve CVE-2025-31958 1 source, 1 claim · Watch

NVD writes:
HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking. the claim
Severity
HIGH NVD
CVSS
8.2 NVD
Vendor
HCLSoftware NVD
Product
BigFix Service Management (SM) NVD
CWE
CWE-444 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-04-21first spoke of it: HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.NVD

HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.

What it is to other things

affectshcltech/bigfix_service_management
NVD
made_byhcltech
NVD

In words only, so not counted until a person confirms one:

made_byhclsoftware
NVD says “HCLSoftware”
affectshclsoftware/bigfix_service_management_sm
NVD says “HCLSoftware · BigFix Service Management (SM)”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD8.2
receipt
Source
NVD
Its words
8.2
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC8.2
2026-10-02 12:00 UTC3.7
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-444
receipt
Source
NVD
Its words
CWE-444
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-444
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDBigFix Service Management (SM)
receipt
Source
NVD
Its words
BigFix Service Management (SM)
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDHCLSoftware
receipt
Source
NVD
Its words
HCLSoftware
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "BigFix Service Management (SM)",
            "vendor": "HCLSoftware",
            "versions": [
              {
                "status": "affected",
                "version": "23"
              }
            ]
          }
        ],
        "source": "psirt@hcl.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*",
                "matchCriteriaId": "4D915AC1-7C2B-497D-9A77-9726954B2282",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking."
      },
      {
        "lang": "es",
        "value": "HCL BigFix Service Management es susceptible al Contrabando de Solicitudes HTTP. Las vulnerabilidades de contrabando de solicitudes HTTP surgen cuando los sitios web enrutan solicitudes HTTP a través de servidores web con análisis HTTP inconsistente. El Contrabando HTTP explota inconsistencias en el análisis de solicitudes entre servidores front-end y back-end, permitiendo a los atacantes eludir los controles de seguridad y realizar ataques como el envenenamiento de caché o el secuestro de solicitudes."
      }
    ],
    "id": "CVE-2025-31958",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 1.4,
          "source": "psirt@hcl.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-31958",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-21T19:32:02.512507Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-21T15:16:35.440",
    "references": [
      {
        "source": "psirt@hcl.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124209"
      }
    ],
    "sourceIdentifier": "psirt@hcl.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-444"
          }
        ],
        "source": "psirt@hcl.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

HCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP requests through web servers with inconsistent HTTP parsing. HTTP Smuggling exploits inconsistencies in request parsing between front-end and back-end servers, allowing attackers to bypass security controls and perform attacks like cache poisoning or request hijacking.
zetlyn/cve-nvd · 2026-04-21
automatable no cvss 8.2 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N cwe CWE-444 exploitation none product BigFix Service Management (SM) severity HIGH status Analyzed technical_impact partial vendor HCLSoftware source