RubySec

Providing security resources for the Ruby community

CVE-2026-38969 (webrick): ruby webrick through v1.9.2 WEBrick reparses trailer

ruby webrick through v1.9.2 WEBrick reparses trailer

Published: July 02, 2026

SECURITY IDENTIFIERS

GEM

webrick

PATCHED VERSIONS

None available.

DESCRIPTION

ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling.

RELATED