{"id":"GHSA-8m85-wqg7-c529","summary":"SAP Approuter Vulnerable to HTTP Request Smuggling","details":"Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.","aliases":["CVE-2026-27690"],"modified":"2026-09-01T21:40:52.618887Z","published":"2026-07-14T03:31:35Z","database_specific":{"cwe_ids":["CWE-444"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-09-01T21:20:31Z","nvd_published_at":"2026-07-14T01:16:17Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27690"},{"type":"WEB","url":"https://me.sap.com/notes/3720138"},{"type":"WEB","url":"https://url.sap/sapsecuritypatchday"}],"affected":[{"package":{"name":"@sap/approuter","ecosystem":"npm","purl":"pkg:npm/%40sap/approuter"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"20.10.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-8m85-wqg7-c529/GHSA-8m85-wqg7-c529.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}