VYPR

rouille

by Theopaid

CVEs (3)

  • CVE-2026-67182HigJul 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without…

  • CVE-2026-66754MedJul 28, 2026
    risk 0.38cvss 5.9epss 0.00

    Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a…

  • CVE-2026-66746MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A) bytes into attacker-controlled input. Attackers can exploit percent-decoded…