CVE-2026-40562
HIGHGazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence
Title source: cnaDescription
Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
References (4)
Core 4
Core References
Release Notes release-notes
https://metacpan.org/release/KAZEBURO/Gazelle-0.50/changes
Scores
CVSS v3
7.5
EPSS
0.0032
EPSS Percentile
23.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-444
Status
published
Products (2)
KAZEBURO/Gazelle
< 0.49
kazeburo/gazelle
< 0.50
Published
May 06, 2026
Tracked Since
May 06, 2026