References https://learn.microsoft.com/zh-cn/security-updates/securitybulletins/2013/ms13-039 https://www.hkcert.org/tc/security-bulletin/microsoft-windows-httpsys-denial-of-service-vulnerability https://support.microsoft.com/en-gb/topic/ms15-034-vulnerability-in-http-sys-could-allow-remote-code-execution-april-14-2015-e8755c1e-c5a8-fa75-c7b1-32087b127850 https://nvd.nist.gov/vuln/detail/cve-2015-1635 https://isc.sans.edu/diary/19583 https://support.microsoft.com/zh-cn/topic/ms16-049-http-sys-%E5%AE%89%E5%85%A8%E6%9B%B4%E6%96%B0%E7%A8%8B%E5%BA%8F-2016-%E5%B9%B4-4-%E6%9C%88-12-%E6%97%A5-a73e8caf-b36d-b60f-e1be-19c79464ee4c https://www.nsfocus.net/vulndb/143865 https://www.sbr-info.com/fuwu/ld/639.html https://www.secrss.com/articles/54184 https://www.sentinelone.com/vulnerability-database/cve-2026-33096/ https://windowsforum.com/threads/cve-2026-49160-http-sys-dos-patch-tuesday-urgency-for-windows-web-stack.424687/ https://www.rapid7.com/db/vulnerabilities/msft-cve-2023-32084/
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java DeserializationPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoC迈普无线网络管理系统 /form/exportConfigByHttp 信息泄露漏洞Apache HTTP/2 双重释放漏洞(CVE-2026-23918)瑞友天翼应用虚拟化系统 /hmrao.php getCurlHttpGet 服务器端请求伪造漏洞NGINX ngx_http_rewrite_module 堆缓冲区溢出漏洞PoCCVE-2025-62168: Squid Proxy - HTTP Authentication Credentials DisclosurePoCCVE-2026-40466: Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport BypassPoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges Actuator