HTTP Request Smuggling Vulnerability in Rouille Proxy Implementation
CVE-2026-67181
Key Information:
Badges
What is CVE-2026-67181?
Rouille, a HTTP server framework, has a vulnerability in versions 0.3.3 through 3.6.2 that allows remote attackers to exploit improper header forwarding in its proxy implementation. This flaw occurs when the proxy forwards the client's Transfer-Encoding header to upstream servers without proper modification, even after the request body has already been de-chunked. This can lead to CL.TE desynchronization attacks, enabling attackers to manipulate HTTP message boundaries and potentially generate unauthorized requests on backend servers.
Affected Version(s)
rouille 0.3.3 <= 3.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
