tomaka rouille是tomaka个人开发者的一个Rust的Web开发框架。 tomaka rouille 0.3.3版本至3.6.2版本存在输入验证错误漏洞,该漏洞源于代理实现中不当的标头转发,导致HTTP请求夹带攻击,使远程攻击者能够使HTTP消息边界不同步。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: HTTP request smuggling via Transfer-Encoding forwarding — backend received smuggled request containing PROOF_782aa5338b84aa1a after TE:chunked framing header
| CVE-2026-67182 | 7.5 HIGH | Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection |
| CVE-2026-66754 | 5.9 MEDIUM | Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding |
| CVE-2026-66746 | 5.4 MEDIUM | Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection |
No comments yet