Logo
vulnerabilityCVE-2026-32239
Name
CVE-2026-32239
Source
NVD ( link)Debian ( link)
Description
Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
capnproto
Patched

Vulnerability Ratings#


6.3
CVSSv4
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.10.4
Patched
yocto
kirkstone
0.9.2
Patched
yocto
master
1.4.0
Not Affected
yocto
scarthgap
1.0.2
Patched

Resolved with patches#


capnproto (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix HTTP body size integer overflow bugs.
Kenton Varda <kenton@cloudflare.com>
CVE-2026-32239
CVE-2026-32240

capnproto (buildroot:master)

#
Title
Author
Resolve
1
Fix HTTP body size integer overflow bugs.
Kenton Varda <kenton@cloudflare.com>
CVE-2026-32239
CVE-2026-32240

capnproto (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix HTTP body size integer overflow bugs.
Kenton Varda <kenton@cloudflare.com>
CVE-2026-32239
CVE-2026-32240

capnproto (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix HTTP body size integer overflow bugs.
Kenton Varda <kenton@cloudflare.com>
CVE-2026-32239
CVE-2026-32240