Junglewise Threat Intelligence

CVE-2026-67181: Rouille HTTP request smuggling in proxy implementation

CVE-2026-67181 · Severity: high · CVSS 7.2 · Published 2026-07-28

Technologies: Tomaka Rouille. Vendors: Tomaka.

Executive brief

Rouille, a Rust-based web framework, contains a flaw in how it handles web traffic when acting as a proxy. An attacker can send specially crafted requests that trick the backend server into misinterpreting where one request ends and the next begins. This can allow an attacker to bypass security controls, interfere with other users' sessions, or gain unauthorized access to internal systems.

Technical details

An HTTP request smuggling vulnerability exists in Rouille's proxy implementation (src/proxy.rs) due to inconsistent interpretation of Transfer-Encoding headers. The framework's underlying server, tiny_http, de-chunks incoming request bodies, but the proxy module forwards the original 'Transfer-Encoding: chunked' header to upstream backends without modification or adding a Content-Length header. This creates a CL.TE desynchronization condition where the backend expects chunked data but receives a raw body, allowing an attacker to 'smuggle' a second request inside the body of the first. This affects applications using the proxy::proxy or proxy::full_proxy functions. As of the advisory date, no fixed version has been released.

Affected products

  • tomaka Rouille 0.3.3 through 3.6.2

Timeline

  • 2026-07-28: disclosed
  • 2026-07-28: advisory

References

Related threats