CVE-2026-75922Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the time the proxy sees it. The proxy appends that byte string to the upstream base URL, and for an Upgrade tunnel writes it into a request line it serializes itself, re-encoding nothing in either path. The HTTP client that sends the resulting URL does not validate the target either. A path containing %0d%0a therefore arrives at the upstream as a CRLF that ends the request line, and a decoded space, '?' or '#' truncates it the same way. Everything the client writes after the CRLF is read by the upstream as a second request. On the buffered path it arrives on a keep-alive connection the proxy pools and reuses for other clients. Its method, path and headers are all chosen by the client, and the upstream attributes it to the proxy, so it reaches upstream paths that the proxy's own routing does not expose.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-23: 3Technical Details · 2026-08-23: 308-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75922 HTTP Request Smuggling in Reverse::Proxy Before 0.04 via PATH_INFO https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75922

    Post summary

    The text is a concise disclosure of CVE-2026-75922, an HTTP request smuggling flaw in Reverse::Proxy v0.03 and earlier, exploitable via PATH_INFO.

    00001118
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-75922 Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands … https://www.cve.org/CVERecord?id=CVE-2026-75922 ----- Traducción: CVE-2026-75922 Rev… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑75922, detailing the HTTP request smuggling vulnerability in Reverse::Proxy before version 0.04, but provides no PoC, exploit code, active use evidence, or patch information.

    0000031
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-75922 Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands … https://www.cve.org/CVERecord?id=CVE-2026-75922

    Post summary

    The text reports CVE‑2026‑75922, detailing that Reverse::Proxy versions before 0.04 suffer from HTTP request smuggling via a percent‑decoded PATH_INFO, but offers no PoC, exploit code, or patch information.

    000001.3K
    58.0K followersView on X

Explore more