Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.
{ "urgency": "not yet assigned" }