Linuxsecurity
Critical HTTP Request Smuggling Vulnerabilities in Cap'n Proto
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two vulnerabilities (CVE-2026-32239, CVE-2026-32240) in Cap'n Proto were discovered by Chanho Kim and Jihyeok Han, allowing attackers to exploit improper handling of negative Content-Length values and large chunk sizes in HTTP messages. This could lead to HTTP request or response smuggling, potentially affecting systems using Cap'n Proto across multiple Ubuntu versions. The vulnerabilities were published on 2026-03-12. Users are advised to update their systems to the patched versions provided in the advisories. A standard system update will apply the necessary changes. The affected Ubuntu versions include 26.04, 24.04, 22.04, 20.04, and 18.04.
Key Points: • Two critical vulnerabilities in Cap'n Proto could lead to HTTP request smuggling. • Affected Ubuntu versions include 26.04, 24.04, 22.04, 20.04, and 18.04. • Users are advised to apply updates to mitigate the risks associated with these vulnerabilities.