rack-proxy is vulnerable to HTTP Response Smuggling
75
High Risk
rack-proxy forwards a backend response's Content-Length even when the same response also carries Transfer-Encoding, so Net::HTTP dechunks the body while rack-proxy keeps the stale backend-supplied length. A compromised or attacker-influenced backend can set this length shorter than the dechunked body, letting the surplus bytes be read as a separate HTTP response on a reused connection. This affects both the default streaming mode and streaming: false, and can poison a shared connection's response queue for downstream intermediaries or caches. The fix rejects any backend response carrying both headers with 502 before forwarding it, closes the backend connection on rejection, and strips response headers named by backend Connection fields.
You are affected if you are using a version that falls within the vulnerable range.
rack-proxy is vulnerable to HTTP Response Smuggling in versions 0.0.1 - 1.0.2.
Upgrade the rack-proxy library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.