goliath
Async framework for writing API servers
Activity
- Latest release
- 2y ago
- Total releases
- 13
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- First release
- Mar 08, 2011
| Version | Released | |
|---|---|---|
1.0.7
patch
|
1.0.7
patch
Dependencies (34)
+ 26 more |
|
1.0.6
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.6
patch
Dependencies (34)
+ 26 more |
|
1.0.5
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.5
patch
Dependencies (33)
+ 25 more |
|
1.0.4
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.4
patch
Dependencies (30)
+ 22 more |
|
1.0.3
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.3
patch
Dependencies (29)
+ 21 more |
|
1.0.2
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.2
patch
Dependencies (29)
+ 21 more |
|
1.0.1
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.1
patch
Dependencies (29)
+ 21 more |
|
1.0.0
major
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (29)
+ 21 more |
|
1.0.0.beta.1
pre
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
1.0.0.beta.1
pre
Dependencies (29)
+ 21 more |
|
0.9.4
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
0.9.4
patch
Dependencies (23)
+ 15 more |
|
0.9.2
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
0.9.2
patch
Dependencies (23)
+ 15 more |
|
0.9.1
patch
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
0.9.1
patch
Dependencies (19)
+ 11 more |
|
0.9.0
initial
1 CVE
CVE-2020-7671
GHSA-3892-2r52-p65m
SNYK-RUBY-GOLIATH-569136
May 24, 2021
HTTP Request Smuggling in goliath
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
goliath through 1.0.6 allows request smuggling attacks where goliath is used as a backend and a frontend proxy also being vulnerable. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Affected versions
0.9.0
0.9.1
0.9.2
0.9.4
1.0.0
1.0.0.beta.1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
References Updated Jul 08, 2026 · Source: OSV.dev |
0.9.0
initial
Dependencies (17)
+ 9 more |