mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
- CVE-2026-32239:
Cap'n Proto is a data interchange format and capability-based RPC
system. Prior to 1.4.0, a negative Content-Length value was converted
to unsigned, treating it as an impossibly large length instead. In
theory, this bug could enable HTTP request/response smuggling. This
vulnerability is fixed in 1.4.0.
For more information, see:
- https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpm
- https://www.cve.org/CVERecord?id=CVE-2026-32239
- CVE-2026-32240:
Cap'n Proto is a data interchange format and capability-based RPC
system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a
chunk's size parsed to a value of 2^64 or larger, it would be
truncated to a 64-bit integer. In theory, this bug could enable HTTP
request/response smuggling. This vulnerability is fixed in 1.4.0.
For more information, see:
- https://github.com/capnproto/capnproto/security/advisories/GHSA-vpcq-mx5v-32wm
- https://www.cve.org/CVERecord?id=CVE-2026-32240
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>