216.73.216.233

CVE-2026-32240

· Published 12/03/2026 20:16 · Modified 12/03/2026 21:07

Labels: CVE-2026-32240 2026-03-12CVE-2026-32240CWE-197[email protected]

Essential information

Published
12/03/2026 20:16
Modified
12/03/2026 21:07
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cap'n proto / cap'n proto cpe:2.3:a:cap'n_proto:cap'n_proto:<1.4.0:*:*:*:*:*:*:*

References