From 7064dc5a112d11f20029a3a0c6f6d437e72b387e Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:11:09 -0400 Subject: [PATCH 1/2] One new rack-proxy advisory --- gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml | 53 +++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml diff --git a/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml b/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml new file mode 100644 index 0000000000..b00cb3d0ed --- /dev/null +++ b/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml @@ -0,0 +1,53 @@ +--- +gem: rack-proxy +ghsa: 42qh-8mx8-7wqm +url: https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm +title: HTTP response smuggling via ambiguous backend response + framing in rack-proxy 1.x +date: 2026-09-25 +description: | + ## Summary + + rack-proxy 1.0.0 through 1.0.2 can forward an incorrect Content-Length + when a backend response contains both Transfer-Encoding and Content-Length. + Net::HTTP removes chunked framing from the body, while rack-proxy + strips Transfer-Encoding but retains the backend-supplied Content-Length. + This affects both the default streaming mode and streaming: false. + + ## Impact and Preconditions + + A malicious, compromised, or attacker-influenced backend can supply + a length shorter than the dechunked body. When a frontend Rack handler + trusts this length and uses persistent connections, surplus bytes + can be interpreted as a subsequent HTTP response, allowing response-queue + poisoning and potentially affecting intermediaries or caches. + + The reporter demonstrated downstream desynchronization with + WEBrick 1.9.2 via Rackup::Handler. Other handlers may close or + reframe the response; end-to-end exploitability depends on the + deployment. The inconsistent Rack response was confirmed in both + streaming modes. No opt-in setting is needed for the vulnerable + response handling. + + ## Credit + + Thanks to oss-security-shop for privately reporting the + vulnerability and providing a detailed reproduction. +unaffected_versions: + - "< 1.0.0" +patched_versions: + - ">= 1.0.3" +related: + url: + - https://rubygems.org/gems/rack-proxy/versions/1.0.3 + - https://github.com/ncr/rack-proxy/releases/tag/v1.0.3 + - https://github.com/ncr/rack-proxy/commit/9886359a29c6dbccef8b5d174514649a2ef08296 + - https://github.com/ncr/rack-proxy/security/advisories/GHSA-42qh-8mx8-7wqm +notes: | + - "High" severify and no CVE or cvss scores in GHSA URL. + - From GHSA URL: "Affected versions: + - Confirmed affected: rack-proxy 1.0.0, 1.0.1, and 1.0.2. + - Fixed in the 1.x series: 1.0.3, released September 25, 2026. + - Versions 2.0.0 and later already reject this ambiguous response framing. + - Versions before 1.0.0 were not assessed for this advisory; + they are not asserted to be unaffected.' From 7d43e9305a25139a8ecb0646286e0654b026f541 Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Sun, 27 Sep 2026 08:34:38 -0400 Subject: [PATCH 2/2] Removed unaffected_patches field/value Removed 'unaffected_versions' section from the vulnerability report. --- gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml | 2 -- 1 file changed, 2 deletions(-) diff --git a/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml b/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml index b00cb3d0ed..179553e2a3 100644 --- a/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml +++ b/gems/rack-proxy/GHSA-42qh-8mx8-7wqm.yml @@ -33,8 +33,6 @@ description: | Thanks to oss-security-shop for privately reporting the vulnerability and providing a detailed reproduction. -unaffected_versions: - - "< 1.0.0" patched_versions: - ">= 1.0.3" related: