PT-2025-26617 · Ruby+7 · Ruby Webrick+7

Published

2023-09-13

·

Updated

2025-11-26

·

CVE-2025-6442

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Ruby WEBrick (affected versions not specified)
Description: The issue concerns an HTTP Request Smuggling Vulnerability in Ruby WEBrick's read header function. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

AZL-64352
AZL-64355
AZL-64364
AZL-64367
BDU:2025-10911
CVE-2025-6442
GHSA-R995-Q44H-HR64
OESA-2025-1930
SUSE-SU-2025:02739-1
SUSE-SU-2025:02739-2
SUSE-SU-2025:4264-1
SUSE-SU-2025_02739-1
SUSE-SU-2025_02739-2
USN-7709-1
USN-7840-1
ZDI-25-414

Affected Products

Alt Linux
Debian
Linuxmint
Apple Macos
Red Os
Ruby Webrick
Suse
Ubuntu