VDB

CVE-2026-40561

CVE-2026-40561 PUBLISHED

Reported by CPANSec · Published May 3, 2026

Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

EPSS 0.01% · 1.9th percentile

Risk Scores

EPSS Score
0.01%
1.9th percentile

Affected Products

VendorProductVersions
KAZUHOStarlet0
KAZUHOStarlet0

Timeline

  • May 3, 2026 CVE Published
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
  • May 28, 2026 EPSS Score

References

  • patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›