VDB
CVE-2026-40561
CVE-2026-40561
PUBLISHED
Reported by CPANSec · Published May 3, 2026
Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
EPSS 0.01% · 1.9th percentile
Risk Scores
EPSS Score
0.01%
1.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| KAZUHO | Starlet | 0 |
| KAZUHO | Starlet | 0 |
Timeline
- May 3, 2026 CVE Published
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
- May 27, 2026 EPSS Score
- May 28, 2026 EPSS Score