HTTP-Daemon: Improper header handling — GLSA 202608-10

A vulnerability was found in HTTP-Daemon allowing header manipulation or filter bypass.

Affected packages

dev-perl/HTTP-Daemon on all architectures
Affected versions < 6.160.0
Unaffected versions >= 6.160.0

Background

HTTP-Daemon provides a base class for simple HTTP servers.

Description

Inconsistent Interpretation of HTTP Requests.

Impact

The bug could potentially be exploited to gain privileged access to APIs or poison intermediate caches.

Workaround

There is no known workaround at this time.

Resolution

All HTTP-Daemon users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=dev-perl/HTTP-Daemon-6.160.0"
 

References

Release date
August 14, 2026

Latest revision
August 14, 2026: 1

Severity
normal

Exploitable
remote

Bugzilla entries