{"id":"CVE-2026-40560","summary":"Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence","details":"Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.\n\nStarman incorrectly prioritizes \"Content-Length\" over \"Transfer-Encoding: chunked\" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence.\n\nAn attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.","modified":"2026-05-28T03:53:19.703321408Z","published":"2026-04-28T23:46:37.780Z","related":["openSUSE-SU-2026:10757-1"],"database_specific":{"cna_assigner":"CPANSec","cwe_ids":["CWE-444"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40560.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/29/1"},{"type":"WEB","url":"https://cpan.org/modules"},{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40560.json"},{"type":"ADVISORY","url":"https://metacpan.org/release/MIYAGAWA/Starman-0.4018/changes"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40560"},{"type":"FIX","url":"https://github.com/miyagawa/Starman/commit/ced205f0805027e9d9c0731f8c40b104220604ed.patch"},{"type":"PACKAGE","url":"https://github.com/miyagawa/Starman"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/miyagawa/starman","events":[{"introduced":"0"},{"fixed":"636cd8b04e0fb5caba3fb9d24a4dcfc9074c0d1c"}]}],"versions":["0.4017","0.4016","0.4015","0.4014","0.4013","0.4011","0.4010","0.4009","0.4008","0.4007","0.4006","0.4005","0.4004","0.4003","0.4002","0.4001","0.4000","0.3014","0.3013","0.3012","0.3011","0.3010","0.3009","0.3008","0.3007","0.3006","0.3005","0.3004","0.3003","0.3002","0.3001","0.3000","0.29_90","0.2014","0.2013","0.2012","0.2011","0.2010","0.2009","0.2008_2","0.2008_1","0.2008","0.2007","0.2006","0.2005","0.2004","0.2003","0.2002","0.2001","0.2000","0.1007","0.1006","0.1005","0.1004","0.1003","0.1002","0.1001","0.1000"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-40560.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}