Skip to content

Commit 09f7b69

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@b366c7e
1 parent 406813f commit 09f7b69

1 file changed

Lines changed: 59 additions & 0 deletions

File tree

Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-42qh-8mx8-7wqm (rack-proxy): HTTP response smuggling via ambiguous backend
4+
response framing in rack-proxy 1.x'
5+
comments: false
6+
categories:
7+
- rack-proxy
8+
advisory:
9+
gem: rack-proxy
10+
ghsa: 42qh-8mx8-7wqm
11+
url: https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm
12+
title: HTTP response smuggling via ambiguous backend response framing in rack-proxy
13+
1.x
14+
date: 2026-09-25
15+
description: |-
16+
## Summary
17+
18+
rack-proxy 1.0.0 through 1.0.2 can forward an incorrect Content-Length
19+
when a backend response contains both Transfer-Encoding and Content-Length.
20+
Net::HTTP removes chunked framing from the body, while rack-proxy
21+
strips Transfer-Encoding but retains the backend-supplied Content-Length.
22+
This affects both the default streaming mode and streaming: false.
23+
24+
## Impact and Preconditions
25+
26+
A malicious, compromised, or attacker-influenced backend can supply
27+
a length shorter than the dechunked body. When a frontend Rack handler
28+
trusts this length and uses persistent connections, surplus bytes
29+
can be interpreted as a subsequent HTTP response, allowing response-queue
30+
poisoning and potentially affecting intermediaries or caches.
31+
32+
The reporter demonstrated downstream desynchronization with
33+
WEBrick 1.9.2 via Rackup::Handler. Other handlers may close or
34+
reframe the response; end-to-end exploitability depends on the
35+
deployment. The inconsistent Rack response was confirmed in both
36+
streaming modes. No opt-in setting is needed for the vulnerable
37+
response handling.
38+
39+
## Credit
40+
41+
Thanks to oss-security-shop for privately reporting the
42+
vulnerability and providing a detailed reproduction.
43+
patched_versions:
44+
- ">= 1.0.3"
45+
related:
46+
url:
47+
- https://rubygems.org/gems/rack-proxy/versions/1.0.3
48+
- https://github.com/ncr/rack-proxy/releases/tag/v1.0.3
49+
- https://github.com/ncr/rack-proxy/commit/9886359a29c6dbccef8b5d174514649a2ef08296
50+
- https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm
51+
notes: |
52+
- "High" severify and no CVE or cvss scores in GHSA URL.
53+
- From GHSA URL: "Affected versions:
54+
- Confirmed affected: rack-proxy 1.0.0, 1.0.1, and 1.0.2.
55+
- Fixed in the 1.x series: 1.0.3, released September 25, 2026.
56+
- Versions 2.0.0 and later already reject this ambiguous response framing.
57+
- Versions before 1.0.0 were not assessed for this advisory;
58+
they are not asserted to be unaffected.'
59+
---

0 commit comments

Comments
 (0)