USN-8571-2: Apache HTTP Server regression
USN-8571-2
Chanho Kim and Jihyeok Han discovered that Cap'n Proto incorrectly handled negative Content-Length values or excessively large chunk sizes when processing HTTP messages. An attacker could possibly use these issues to cause HTTP messages to be interpreted inconsistently, resulting in HTTP request or response smuggling. (CVE-2026-32239, CVE-2026-32240)
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
The publication date reported by the vendor.
We collected the advisory from the official source.
Our collector saw this advisory during a later source check.