← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 23, 2026 · 19:16via CVEFeed

CVE-2026-75922 - Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line

Brief

CVE ID : CVE-2026-75922

Published : Aug. 23, 2026, 7:16 p. m.

  • 1 hour, 55 minutes ago

Description : Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line.

PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the time the proxy sees it. The proxy appends that byte string to the upstream base URL, and for an Upgrade tunnel writes it into a request line it serializes itself, re-encoding nothing in either path. The HTTP client that sends the resulting URL does not validate the target either.

A path containing %0d%0a therefore arrives at the upstream as a CRLF that ends the request line, and a decoded space, '?' or '#' truncates it the same way.

Read more on CVEFeed