Back to CVE List

CVE-2026-40560

Vulnerability Description

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.

Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence.

An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-444
Source
NVD
Vendor
MIYAGAWA
Product
Starman

External References

Discussion (0)

Add Comment

No comments yet. Be the first!