Ruby-lang Webrick 1.8.0 for Ruby

CPE Details

Ruby-lang Webrick 1.8.0 for Ruby
1.8.0
2023-08-01
16h50 +00:00
2023-08-05
00h58 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ruby-lang:webrick:1.8.0:*:*:*:*:ruby:*:*

Informations

Vendor

ruby-lang

Product

webrick

Version

1.8.0

Target Software

ruby

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-6442 2025-06-25 16h52 +00:00 Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.
5.9
Medium