Fedora alert FEDORA-2026-b94aad33a5 (perl-Starman)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 43 Update: perl-Starman-0.4018-1.fc43 | |
| Date: | Fri, 08 May 2026 01:03:22 +0000 | |
| Message-ID: | <20260508010322.D79C07B151@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b94aad33a5 2026-05-08 01:00:54.371992+00:00 -------------------------------------------------------------------------------- Name : perl-Starman Product : Fedora 43 Version : 0.4018 Release : 1.fc43 URL : https://metacpan.org/dist/Starman Summary : High-performance preforking PSGI/Plack web server Description : Starman is a PSGI perl web server that has unique features such as high performance, preforking, use of signals and a small memory footprint. It is PSGI compatible and offers HTTP/1.1 support. -------------------------------------------------------------------------------- Update Information: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy. This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 29 2026 Emmanuel Seyman <emmanuel@seyman.fr> - 0.4018-1 - Update to 0.4018 (which contains a fix for CVE-2026-40560) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463491 - perl-Starman-0.4018 is available https://bugzilla.redhat.com/show_bug.cgi?id=2463491 [ 2 ] Bug #2463795 - CVE-2026-40560 perl-Starman: Starman: HTTP Request Smuggling via improper header precedence [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463795 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b94aad33a5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
