Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: perlPackages.Starman

Found 1 matching suggestions

View:
Compact
Detailed
updated 12 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • perlPackages.CatalystXScriptServerStarman
    • perl5Packages.CatalystXScriptServerStarman
    • perl538Packages.CatalystXScriptServerStarman
    • perl540Packages.CatalystXScriptServerStarman
  • @LeSuisse ignored reference https://d…
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

Affected products

Starman
  • <0.4018

Matching in nixpkgs

Ignored packages (4)