


Perceptive Security
SOC/SIEM Consultancy

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 17:04:58
Source:
nvd.nist.gov
Web Technologies, Network Infrastructure
Rouille versions 0.3.3 through 3.6.2 contain an HTTP request smuggling vulnerability tracked as CVE-2026-67181. The flaw exists in the proxy implementation within src/proxy.rs, which incorrectly forwards the client's Transfer-Encoding header to upstream backends without modification. Since the body has already been de-chunked by the tiny_http library before forwarding, a mismatch is created between what the proxy and backend believe about the request body boundaries. This enables CL.TE (Content-Length/Transfer-Encoding) desynchronization attacks, allowing remote unauthenticated attackers to manipulate where the backend perceives the end of a request body. Exploitation could lead to cache poisoning, request hijacking, or security control bypass. The vulnerability affects a wide range of Rouille versions and targets deployments using its built-in proxy functionality.
Technical details
Mitigation steps:
Affected products:
Rouille 0.3.3 through 3.6.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67181
https://github.com/theopaid/HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-
https://www.vulncheck.com/advisories/rouille-http-request-smuggling-via-proxy-transfer-encoding-header
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
