Executive brief
Gazelle, a high-performance web server for Perl, is vulnerable to a security flaw in how it handles web traffic. By sending specially crafted requests, an attacker can bypass security controls or interfere with other users' sessions when the server is used behind a reverse proxy. This could lead to unauthorized actions or data manipulation within web applications.
Technical details
Gazelle (up to version 0.49) fails to follow RFC 7230 requirements regarding HTTP header precedence. Specifically, the server incorrectly prioritizes the 'Content-Length' header over 'Transfer-Encoding: chunked' when both are present in a single request. This inconsistency allows a remote, unauthenticated attacker to perform HTTP Request Smuggling (CWE-444) if Gazelle is deployed behind a front-end reverse proxy that follows standard RFC precedence. An attacker can use this to 'smuggle' a second request inside the body of the first, potentially bypassing security filters or poisoning the web cache. The issue is resolved in version 0.50.
Affected products
- kazeburo Gazelle up to 0.49
Timeline
- 2026-04-12: other: Issue identified by CPANSec
- 2026-04-29: other: Issue reported to software maintainer
- 2026-05-06: advisory
- 2026-05-07: patched: Version 0.50 released