CVE Database
/

CVE-2026-32239

Back to search

CVE-2026-32239

Published: Mar 12, 2026

Modified: Mar 13, 2026

PUBLISHED

Description

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.

VendorProductVersions

capnproto

capnproto

affected
< 1.4.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now