Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
https://lists.debian.org/debian-lts-announce/2020/05/msg00003.html
https://lists.debian.org/debian-lts-announce/2020/04/msg00028.html
https://lists.debian.org/debian-lts-announce/2018/02/msg00015.html
http://www.apsis.ch/pound/pound_list/archive/2016/2016-10/1477235279000