๐Ÿ” CVE Alert

CVE-2026-40560

UNKNOWN 0.0

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

CWE CWE-444
Vendor miyagawa
Product starman
Published Apr 28, 2026
Last Updated Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for miyagawa starman

Be the first to know when new unknown vulnerabilities affecting miyagawa starman are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MIYAGAWA / Starman
0 < 0.4018

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/miyagawa/Starman/commit/ced205f0805027e9d9c0731f8c40b104220604ed.patch metacpan.org: https://metacpan.org/release/MIYAGAWA/Starman-0.4018/changes datatracker.ietf.org: https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.3

Credits

CPANSec