Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Arch Linux 2026 perl-HTTPD-CGI Significant URI Parsing Flaw 3c5a7d4b5e

fedora
Calendar Grey May 8, 2026
Dist Fedora Esm H88
Starman update for Fedora addresses HTTP request smuggling risk by enforcing header precedence to prevent exploitation.
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence

Summary

Starman is a PSGI perl web server that has unique features such as high

performance, preforking, use of signals and a small memory footprint. It is PSGI

compatible and offers HTTP/1.1 support.

Update Information:

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy. This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length.

Change Log

* Wed Apr 29 2026 Emmanuel Seyman - 0.4018-1 - Update to 0.4018 (which contains a fix for CVE-2026-40560)

References


[ 1 ] Bug #2463491 - perl-Starman-0.4018 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463491 [ 2 ] Bug #2463795 - CVE-2026-40560 perl-Starman: Starman: HTTP Request Smuggling via improper header precedence [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463795

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b94aad33a5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: perl-Starman
Product: Fedora 43
Version: 0.4018
Release: 1.fc43
Summary: High-performance preforking PSGI/Plack web server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here