Intel

AIKIDO-2026-58381

rack-proxy is vulnerable to HTTP Response Smuggling

HTTP Response SmugglingGHSA-42qh-8mx8-7wqm Published Yesterday

75

High Risk

This Affects:

RUBYrack-proxy
0.0.1 - 1.0.2
Fixed in 1.0.3
Are you affected? Scan for Free

TL;DR

rack-proxy forwards a backend response's Content-Length even when the same response also carries Transfer-Encoding, so Net::HTTP dechunks the body while rack-proxy keeps the stale backend-supplied length. A compromised or attacker-influenced backend can set this length shorter than the dechunked body, letting the surplus bytes be read as a separate HTTP response on a reused connection. This affects both the default streaming mode and streaming: false, and can poison a shared connection's response queue for downstream intermediaries or caches. The fix rejects any backend response carrying both headers with 502 before forwarding it, closes the backend connection on rejection, and strips response headers named by backend Connection fields.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

rack-proxy is vulnerable to HTTP Response Smuggling in versions 0.0.1 - 1.0.2.

How to fix this

Upgrade the rack-proxy library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform