CVE-2026-32239

unknown
EUVD alias: EUVD-2026-11687
Published 2026-08-19 · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

Cap'n Proto vulnerabilities

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-32239 NameCVE-2026-32239 DescriptionCap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec,…

CVE-2026-32239

NameCVE-2026-32239
DescriptionCap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1130877

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
capnproto (PTS)bullseye0.7.0-7vulnerable
bookworm0.9.2-2vulnerable
trixie1.1.0-2vulnerable
forky, sid1.4.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
capnprotosourceexperimental1.4.0-1
capnprotosource(unstable)1.4.0-21130877

Notes

[trixie] - capnproto <no-dsa> (Minor issue)
[bullseye] - capnproto <postponed> (minor issue)
https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpm
Fixed by: https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36 (v1.4.0)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - capnproto <no-dsa> (Minor issue)[bullseye] - capnproto <postponed> (minor issue)https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpmFixed by: https://github.com/capnproto/capnproto/commit/2744b3c012b4aa3c31cefb61ec656829fa5c0e36 (v1.4.0)

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected
sid Fixed 1.4.0-2
forky Fixed 1.4.0-2
bullseye Affected
bookworm Affected
ubuntu Ubuntu Fixed 5 releases
VersionStatusFixed in
resolute Fixed 1.1.0-2.1ubuntu0.1~esm1
noble Fixed 1.0.1-4ubuntu0.1~esm1
jammy Fixed 0.8.0-2ubuntu2+esm1
focal Fixed 0.7.0-6ubuntu0.1~esm1
bionic Fixed 0.6.1-1ubuntu1+esm1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.