Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40560

Опубликовано: 29 апр. 2026
Источник: debian
EPSS Низкий

Описание

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
starmanfixed0.4018-1package
starmanfixed0.4018-0+deb13u1trixiepackage
starmanno-dsabookwormpackage
starmanpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/39426182/

  • Fixed by: https://github.com/miyagawa/Starman/commit/ced205f0805027e9d9c0731f8c40b104220604ed (0.4018)

EPSS

Процентиль: 40%
0.00487
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

CVSS3: 7.5
nvd
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

CVSS3: 7.5
github
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

EPSS

Процентиль: 40%
0.00487
Низкий