CVE-2025-6442

unknown
Published 2025-06-26 · Modified 2025-06-30
CVSS v3
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
CVSS v2
VIR risk

Description

Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-6442

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-6442.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormaffected
debian debianforkyfixed1.9.1-1
debian debiansidfixed1.9.1-1
debian debiantrixiefixed1.9.1-1

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemswebrick<>= 1.8.2>= 1.8.2
ruby RubyGemswebrick<1.8.21.8.2

References

Verify integrity in audit chain (admin only). AS-IS.