Junglewise Threat Intelligence

CVE-2026-66746: Rouille HTTP response splitting in response headers

CVE-2026-66746 · Severity: medium · CVSS 5.4 · Published 2026-07-28

Technologies: Tomaka Rouille. Vendors: Tomaka.

Executive brief

Rouille, a web server library for the Rust programming language, contains a flaw in how it handles web traffic headers. An attacker can send specially crafted data that tricks the server into splitting a single response into two, allowing them to inject malicious instructions. This can be used to bypass security policies, hijack user sessions, or serve fraudulent content to other visitors.

Technical details

Rouille versions 0.4.0 through 3.6.2 are vulnerable to HTTP response splitting (CWE-113) due to improper neutralization of CRLF sequences (0x0D and 0x0A) in HTTP headers. The vulnerability occurs when percent-decoded query parameters or unvalidated Cookie header values are interpolated directly into response headers like Set-Cookie. A remote attacker can exploit this by providing input containing carriage return or line feed characters, allowing them to terminate the current header and inject arbitrary new headers or a second response body. This can lead to cache poisoning, session fixation, and the bypass of security mechanisms such as Content Security Policy (CSP) or Cross-Origin Resource Sharing (CORS). Exploitation typically requires some level of user interaction to trigger the malicious request.

Affected products

  • tomaka rouille 0.4.0 through 3.6.2

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References

Related threats