Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 9 perl-Starman Important HTTP Request Smuggling MGASA-2026-0119

mageia
Calendar Grey May 7, 2026
Dist Mageia Esm H88
Updated perl-Starman packages address critical security fault, allowing attackers to exploit HTTP request smuggling risks in Mageia.
MGASA-2026-0119 - Updated perl-Starman packages fix security vulnerability

Summary

Description: Starman versions before 0.4018 for Perl allow HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

References

- https://bugs.mageia.org/show_bug.cgi?id=35448

- https://www.openwall.com/lists/oss-security/2026/04/29/1

- https://metacpan.org/release/MIYAGAWA/Starman-0.4018/changes

- https://datatracker.ietf.org/doc/html/rfc7230#section-3.3.3

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-40560

Resolution

SRPMS

- 9/core/perl-Starman-0.401.800-1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 07 May 2026
URL: https://advisories.mageia.org/MGASA-2026-0119.html
Type: security
CVE: CVE-2026-40560

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here