DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Upgrade WEBrick to the latest release that fixes the duplicate Content‑Length parsing bug.
- If upgrading immediately is not feasible, configure an upstream reverse proxy or load balancer to strip or reject any trailing Content‑Length headers from incoming requests, following CWE‑444 mitigation guidance.
- Deploy application‑layer firewall or WAF rules that detect and block requests containing duplicate or malformed Content‑Length headers until the underlying server is patched, in compliance with CWE‑444 best practices.
Generated by OpenCVE AI on July 15, 2026 at 10:03 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
cvssV3_1
|
Tue, 14 Jul 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. NOTE: the Supplier reports that "The project README states that it is suitable for testing and development, and that its developers do not encourage its use to serve production web applications that may be subject to hostile input. It is not a production web server and is not intended to receive traffic from untrusted sources. Request smuggling is only reachable when WEBrick sits behind a proxy and receives hostile traffic in a production deployment, which is the configuration the project documents as discouraged." | DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. |
| References |
|
Fri, 10 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. NOTE: the Supplier reports that "The project README states that it is suitable for testing and development, and that its developers do not encourage its use to serve production web applications that may be subject to hostile input. It is not a production web server and is not intended to receive traffic from untrusted sources. Request smuggling is only reachable when WEBrick sits behind a proxy and receives hostile traffic in a production deployment, which is the configuration the project documents as discouraged." |
| References |
|
Mon, 06 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Fri, 03 Jul 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 03 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WEBrick Request Smuggling via Trailer Content-Length Re‑parsing | webrick: rubygem-webrick: WEBrick: Request smuggling via re-parsing of Content-Length header |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 03 Jul 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WEBrick Request Smuggling via Trailer Content-Length Re‑parsing | |
| Weaknesses | CWE-20 |
Fri, 03 Jul 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruby
Ruby webrick |
|
| Vendors & Products |
Ruby
Ruby webrick |
Thu, 02 Jul 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. | |
| References |
|
Status: REJECTED
Assigner: mitre
Published:
Updated: 2026-07-14T16:58:35.765Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38969
Updated:
Status : Rejected
Published: 2026-07-02T21:16:56.050
Modified: 2026-07-14T17:16:47.000
Link: CVE-2026-38969
OpenCVE Enrichment
Updated: 2026-07-15T10:15:04Z
-
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')