Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b94aad33a5 2026-05-08 01:00:54.371992+00:00 -------------------------------------------------------------------------------- Name : perl-Starman Product : Fedora 43 Version : 0.4018 Release : 1.fc43 URL : https://metacpan.org/dist/Starman Summary : High-performance preforking PSGI/Plack web server Description : Starman is a PSGI perl web server that has unique features such as high performance, preforking, use of signals and a small memory footprint. It is PSGI compatible and offers HTTP/1.1 support. -------------------------------------------------------------------------------- Update Information: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy. This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 29 2026 Emmanuel Seyman - 0.4018-1 - Update to 0.4018 (which contains a fix for CVE-2026-40560) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463491 - perl-Starman-0.4018 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463491 [ 2 ] Bug #2463795 - CVE-2026-40560 perl-Starman: Starman: HTTP Request Smuggling via improper header precedence [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463795 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b94aad33a5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.