[ GLSA 202608-10 ] HTTP-Daemon: Improper header handling

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178674995260.1.12511473889651061737@cdebd0f5f1fc>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-10
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: HTTP-Daemon: Improper header handling
     Date: August 14, 2026
     Bugs: #908905
       ID: 202608-10

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

A vulnerability was found in HTTP-Daemon allowing header manipulation or
filter bypass.

Background
==========

HTTP-Daemon provides a base class for simple HTTP servers.

Affected packages
=================

Package               Vulnerable    Unaffected
--------------------  ------------  ------------
dev-perl/HTTP-Daemon  < 6.160.0     >= 6.160.0

Description
===========

Inconsistent Interpretation of HTTP Requests.

Impact
======

The bug could potentially be exploited to gain privileged access to APIs
or poison intermediate caches.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All HTTP-Daemon users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-perl/HTTP-Daemon-6.160.0"

References
==========

[ 1 ] CVE-2022-31081
      https://nvd.nist.gov/vuln/detail/CVE-2022-31081

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-10

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp/pAAbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZhakQANG2GHsk1+TObu/RK42M
AlOJ5imJEZNJflVyRRCJdbMepCYVUYq1elciWz7LpCfmTk6dWjMyjBL8nd9zpVl7
8XxB9qkFIC+EwAu0i8k6mcPEWkdYbCtMd89CDSeMz/jNl4kqlWupMO1BswX0wMh/
UrZpXHkMsH22yQytYcuSmsUrK08IxIdgSwbjeD/W5Ta17v4RikaKunlP+WWa8Lbi
yn0u3YsbzIEwg5nrh36Xuj7i6e2mFOiF7tx4sbx67JUR+rQAMsEjt3RMCjyi4N12
MARrWv+/StoIDjmQfKGgxzE1OznvukpXkgzx1vimJKBIi50uPVInXDzNE1gwUBUO
aIu9WQa7f6UBpFhuCdISK7N3erRKUUa5bWAckNZj4/DvTuuA8P/2mXDCL1U0Zfkp
CBPx/q66KvPJLssDzGwpTu1V/5EIeKJLWzii25YuIGLo21oG4ddcIuJlHKE+Ek8Q
7bdv4nSrqhbyNq9je+9WFU822Bkd7lmt+qD47LhxEn0jmgi7T5ejVZPXhi7pPqNd
28v9XzIdmrYWFXLlqn5C4bJEkclVipbBjtUGYgREwAwPW6xBxikBppacOfsCJX+1
aAn8hLjpVIRk7S+RzmUf9Fgn5qwaiNVyJ5PU81NPxN/sz/NAFjKK7/Ou4XHySZTr
MgFCfAwhOGqscKV/2fNqa1y3
=GSdo
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.