CVE-2026-40562 POC (Proof-of-Concept)

CVE-2026-40562 POC (Proof-of-Concept)

Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence.
An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

Published: 2026-05-06

CVSS: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Download CVE-2026-40562 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://hokyo.gr/poc-834-cve-2026-7330/

https://hokyo.gr/poc-129-cve-2026-37531/

Copyright 2017- 2025 Hokyo JapanEats ©