Open Source Security mailing list@oss_securityDisclosure
A new vulnerability (CVE‑2026‑40561) has been disclosed for Starlet versions up to 0.31, allowing HTTP request smuggling through improper header precedence.
CVE@CVEnewDisclosure
The text announces CVE-2026-40561, detailing that Starlet (Perl versions ≤0.31) is vulnerable to HTTP Request Smuggling due to improper header precedence between Content-Length and Transfer‑… . No PoC, exploitation, patch, or debunking information is provided.
CVEarity@CVEarityDisclosure
A new CVE-2026-40561 is announced with unknown risk level, impacting multiple unspecified products, and only a link to its NVD entry is provided.
Infoflowcloud@infoflowcloudGeneral
The post announces CVE‑2026‑40561, describing its HTTP Request Smuggling flaw, but offers no PoC, exploit, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
CVE-2026-40561 is disclosed as an HTTP Request Smuggling flaw in Starlet Perl through 0.31, caused by header precedence.