|
| 1 | +--- |
| 2 | +layout: advisory |
| 3 | +title: 'GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend |
| 4 | + response framing in rack-proxy 1.x' |
| 5 | +comments: false |
| 6 | +categories: |
| 7 | +- rack-proxy |
| 8 | +advisory: |
| 9 | + gem: rack-proxy |
| 10 | + ghsa: 42qh-8mx8-7wqm |
| 11 | + url: https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm |
| 12 | + title: HTTP response smuggling via ambiguous backend response framing in rack-proxy |
| 13 | + 1.x |
| 14 | + date: 2026-09-25 |
| 15 | + description: |- |
| 16 | + ## Summary |
| 17 | +
|
| 18 | + rack-proxy 1.0.0 through 1.0.2 can forward an incorrect Content-Length |
| 19 | + when a backend response contains both Transfer-Encoding and Content-Length. |
| 20 | + Net::HTTP removes chunked framing from the body, while rack-proxy |
| 21 | + strips Transfer-Encoding but retains the backend-supplied Content-Length. |
| 22 | + This affects both the default streaming mode and streaming: false. |
| 23 | +
|
| 24 | + ## Impact and Preconditions |
| 25 | +
|
| 26 | + A malicious, compromised, or attacker-influenced backend can supply |
| 27 | + a length shorter than the dechunked body. When a frontend Rack handler |
| 28 | + trusts this length and uses persistent connections, surplus bytes |
| 29 | + can be interpreted as a subsequent HTTP response, allowing response-queue |
| 30 | + poisoning and potentially affecting intermediaries or caches. |
| 31 | +
|
| 32 | + The reporter demonstrated downstream desynchronization with |
| 33 | + WEBrick 1.9.2 via Rackup::Handler. Other handlers may close or |
| 34 | + reframe the response; end-to-end exploitability depends on the |
| 35 | + deployment. The inconsistent Rack response was confirmed in both |
| 36 | + streaming modes. No opt-in setting is needed for the vulnerable |
| 37 | + response handling. |
| 38 | +
|
| 39 | + ## Credit |
| 40 | +
|
| 41 | + Thanks to oss-security-shop for privately reporting the |
| 42 | + vulnerability and providing a detailed reproduction. |
| 43 | + patched_versions: |
| 44 | + - ">= 1.0.3" |
| 45 | + related: |
| 46 | + url: |
| 47 | + - https://rubygems.org/gems/rack-proxy/versions/1.0.3 |
| 48 | + - https://github.com/ncr/rack-proxy/releases/tag/v1.0.3 |
| 49 | + - https://github.com/ncr/rack-proxy/commit/9886359a29c6dbccef8b5d174514649a2ef08296 |
| 50 | + - https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm |
| 51 | + notes: | |
| 52 | + - "High" severify and no CVE or cvss scores in GHSA URL. |
| 53 | + - From GHSA URL: "Affected versions: |
| 54 | + - Confirmed affected: rack-proxy 1.0.0, 1.0.1, and 1.0.2. |
| 55 | + - Fixed in the 1.x series: 1.0.3, released September 25, 2026. |
| 56 | + - Versions 2.0.0 and later already reject this ambiguous response framing. |
| 57 | + - Versions before 1.0.0 were not assessed for this advisory; |
| 58 | + they are not asserted to be unaffected.' |
| 59 | +--- |
0 commit comments