Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32239

Опубликовано: 12 мар. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:capnproto:capnproto:*:*:*:*:*:*:*:*
Версия до 1.4.0 (исключая)

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.5
ubuntu
15 дней назад

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.

CVSS3: 4.8
redhat
15 дней назад

A flaw was found in the KJ-HTTP component of Cap’n Proto. When processing HTTP messages, a negative Content-Length value could be implicitly converted to an unsigned integer, resulting in an extremely large length value. An attacker could exploit this behavior by sending specially crafted HTTP messages containing negative Content-Length values. This may lead to inconsistent interpretation of HTTP message boundaries and could theoretically enable HTTP request or response smuggling scenarios in applications that rely on Cap’n Proto’s HTTP implementation.

CVSS3: 6.5
debian
15 дней назад

Cap'n Proto is a data interchange format and capability-based RPC syst ...

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-190