HTTP Request Smuggling Affecting ruby-webrick package, versions *


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.07% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN12-RUBYWEBRICK-10500695
  • published26 Jun 2025
  • disclosed25 Jun 2025

Introduced: 25 Jun 2025

NewCVE-2025-6442  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

There is no fixed version for Debian:12 ruby-webrick.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ruby-webrick package and not the ruby-webrick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.

The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.