CVE-2025-6442

Vulnerability

CVE-2025-6442

webrick: Ruby WEBrick Request Smuggling Vulnerability

ecosystem: redhat:6, redhat:7, redhat:8, redhat:9

A request smuggling vulnerability has been discovered in the Ruby WEBrick gem. This vulnerability is exploitable when the product is deployed behind a HTTP proxy that fulfills specific conditions.

References
severityM
Moderate

type: vendor

source: secalert@redhat.com

CVSS3.0
6.5MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

AVNetwork
ACHigh
PRNone
UINone
SNot Changed
CLow
IHigh
ANone

source: secalert@redhat.com

 CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

source: secalert@redhat.com

published: 2025-06-25 16:52:24

modified: 2025-07-08 05:11:29

Detection

OR

 unfixed

 

ruby

package type: source

type: version

tag: rhel-6-els:bedace07-9632-525d-a652-045a2f8093cc

OR

 unfixed

 

ruby

package type: source

type: version

tag: rhel-7-extras-including-unpatched:ca6ed3f0-0f32-525d-a652-07357231e4eb

OR

 unfixed

 

ruby

package type: source

type: version

tag: rhel-8-including-unpatched:bbff1360-bf5a-d0cd-688e-e38d049d5890

OR

 unfixed

 

pcs

package type: source

type: version

tag: rhel-9-including-unpatched:435a9219-65b2-f412-2d39-f65c074bc1b9

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub