Junglewise Threat Intelligence

CVE-2026-40560: MIYAGAWA Starman HTTP request smuggling via improper header precedence

CVE-2026-40560 · Severity: high · CVSS 7.5 · Published 2026-04-29

Executive brief

Starman is a high-performance web server for Perl applications. A vulnerability in how it handles incoming web requests allows an attacker to "smuggle" hidden requests past security filters or reverse proxies. This could lead to unauthorized access to internal systems, data exposure, or the bypassing of security controls.

Technical details

Starman incorrectly prioritizes the 'Content-Length' header over 'Transfer-Encoding: chunked' when both are present in an HTTP request. This behavior violates RFC 7230 Section 3.3.3, which requires Transfer-Encoding to take precedence. The vulnerability exists in the '_prepare_env' routine within 'lib/Starman/Server.pm'. An unauthenticated remote attacker can exploit this inconsistency to perform HTTP request smuggling when Starman is deployed behind a front-end reverse proxy. This can result in the bypass of security rules or unauthorized access to other users' sessions. The issue is fixed in version 0.4018.

Affected products

  • MIYAGAWA Starman before 0.4018

Timeline

  • 2026-04-27: patched: Fix committed to repository and version 0.4018 released.
  • 2026-04-28: disclosed: Vulnerability reported to NVD.
  • 2026-04-29: advisory: Public disclosure on oss-security mailing list.

References