Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40560

Опубликовано: 29 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.

Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence.

An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:miyagawa:starman:*:*:*:*:*:perl:*:*
Версия до 0.4018 (исключая)

EPSS

Процентиль: 40%
0.00487
Низкий

7.5 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

CVSS3: 7.5
debian
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling ...

CVSS3: 7.5
github
4 месяца назад

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

EPSS

Процентиль: 40%
0.00487
Низкий

7.5 High

CVSS3

Дефекты

CWE-444