Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-67181

6 дней назад

(Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-67181

6 дней назад

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-67181

6 дней назад

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-fgf8-ph7p-m275

6 дней назад

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-67181

(Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)

CVSS3: 5.4
0%
Низкий
6 дней назад
nvd логотип
CVE-2026-67181

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.

CVSS3: 5.4
0%
Низкий
6 дней назад
debian логотип
CVE-2026-67181

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...

CVSS3: 5.4
0%
Низкий
6 дней назад
github логотип
GHSA-fgf8-ph7p-m275

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends unchanged while transmitting a body already de-chunked by tiny_http, enabling CL.TE desynchronization attacks where attackers control where the backend believes the request body ends.

CVSS3: 5.4
0%
Низкий
6 дней назад

Уязвимостей на страницу