CVE-2026-40560Disclosure(miyagawa / starman)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch miyagawa starman systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • starman

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-29); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
starman

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-29: 4Mentions · 2026-05-22: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-29: 3Technical Details · 2026-05-22: 104-2905-22
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-294
Disclosure4
2026-05-221
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN CVE-2026-40560: Starman before 0.4018 allows HTTP Request Smuggling via Improper Header Precedence https://www.openwall.com/lists/oss-security/2026/04/29/1

    Post summary

    A new CVE-2026-40560 vulnerability has been disclosed: Starman versions prior to 0.4018 suffer from HTTP Request Smuggling due to improper header precedence.

    01071450
    4.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-40560 (CVSS 7.5) Starman for Perl <0.4018 vulnerable to HTTP Request Smuggling via improper header precedence. Attackers can smuggle malicious requests through reverse proxies. Patch immediately to v0.4018+ #CVE #Vulnerability #PatchNow https://t.co/FeSpJrtbcf

    Post summary

    CVE-2026-40560 affects Starman <0.4018, enabling HTTP Request Smuggling; users are urged to apply the v0.4018+ patch immediately.

    0000055
    30 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40560 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40560 #CVE-2026-40560 #CVE #CyberSecurity #InfoSec https://t.co/gSuDf9r4IZ

    Post summary

    The tweet simply announces the existence of CVE-2026-40560, with no further technical, exploit, or mitigation information.

    0000034
    142 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40560 HTTP Request Smuggling in Starman for Perl Before 0.4018 via Header Precedence https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40560

    Post summary

    The post announces CVE-2026-40560, detailing an HTTP request smuggling flaw in Starman for Perl versions prior to 0.4018, without mentioning PoC, exploits, or patches.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40560 Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer… https://www.cve.org/CVERecord?id=CVE-2026-40560

    Post summary

    The text announces a CVE against Starman Perl 0.4018 and earlier, highlighting HTTP Request Smuggling due to header precedence, with no exploit, patch, or PoC details provided.

    00000116
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmiyagawastarman-perl-

Explore more