inets,httpd: Memory Exhaustion via Unenforced maxbodysize During Chunked Body Reception
httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved.
httpd modauth directory protection bypassed by request path casing on case-insensitive filesystems