VYPR

Reverse::Proxy

by Perl Foundation

CVEs (1)

  • CVE-2026-75922MedAug 23, 2026
    risk 0.34cvss 5.3epss 0.00

    Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to an application percent-decoded, so a %XX sequence in the client URL has become a raw byte by the…