tomaka rouille是tomaka个人开发者的一个Rust的Web开发框架。 tomaka rouille 0.1.6版本至3.6.2版本存在异常处理不当漏洞,该漏洞源于Request::remove_prefix函数存在可达断言漏洞,允许远程未认证攻击者通过发送特制的百分号编码URL使服务器崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-67182 | 7.5 HIGH | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection |
| CVE-2026-66746 | 5.4 MEDIUM | Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection |
| CVE-2026-67181 | 5.4 MEDIUM | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header |
No comments yet