VulnerabilityAnalyzed
CVE-2026-32239
This vulnerability is fixed in 1.4.0.
MEDIUM 6.3EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.
- CVSS 4.0
- 6.3 MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.21% probability · 11th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190, CWE-444
- Affected
- capnproto/capnproto
- Source
- security-advisories@github.com
References
- https://capnproto.org/capnproto-c++-1.4.0.tar.gzProduct
- https://capnproto.org/capnproto-c++-win32-1.4.0.zipProduct
- https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36Patch
- https://github.com/capnproto/capnproto/commit/e929f0ba7901a6b8f4b5ba9a4db00af43288cbb0Patch
- https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.