Apsis maintains the Pound reverse proxy and load-balancing application, a focused product that operates at the network request layer of web infrastructure. The observed vulnerability pattern centers on HTTP request and response handling, reflecting the complexity of correctly parsing and forwarding varied HTTP semantics across proxy boundaries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apsis over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2026HIGH Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messa | Dec 31, 2004 | 7.5 | 38 | NO | YES |
CVE-2016-10711CRITICAL Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751. | Jan 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-21245CRITICAL Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711. | Jun 15, 2020 | 9.1 | 28 | NO | NO |
CVE-2005-1391HIGH Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header. | May 3, 2005 | 7.5 | 21 | NO | NO |
CVE-2005-3751MEDIUM HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall protection, and conduct XSS attacks via an | Nov 22, 2005 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apsis.
Media articles that mention a CVE ID that affects a product developed by Apsis — matched by CVE ID, not by vendor name.