webrick
WEBrick is an HTTP server toolkit that can be configured as an HTTPS server, a proxy server, and a virtual-host server.
Activity
- Latest release
- 9mo ago
- Total releases
- 18
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- unknown OR BSD-2-Clause
- First release
- Dec 28, 2011
| Version | Released | |
|---|---|---|
1.9.2
patch
| ||
1.9.1
patch
| ||
1.9.0
minor
| ||
1.8.2
patch
| ||
1.8.0
minor
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.1
patch
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.0
minor
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.1
patch
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.4
patch
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.3
patch
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.6.0
minor
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.5.0
minor
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.4.2
patch
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.4.1
patch
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.4.0
minor
3 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev | ||
1.4.0.beta1
pre
5 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev
CVE-2017-10784
GHSA-369m-2gv6-mw28
May 14, 2022
WEBrick RCE Vulnerability
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name. Affected versions
1.3.1
1.4.0.beta1
Fixed in
1.4.0
References
Updated Mar 13, 2024 · Source: OSV.dev
CVE-2009-4492
GHSA-6mq2-37j5-w6r6
Oct 24, 2017
WEBrick Improper Input Validation vulnerability
Medium
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Affected versions
1.3.1
1.4.0.beta1
Fixed in
1.4.0
References
Updated May 22, 2025 · Source: OSV.dev | ||
1.3.1
initial
5 CVEs
CVE-2025-6442
GHSA-r995-q44h-hr64
Jun 26, 2025
Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
6.5
/ 10
Medium
Network
High
None
None
Unchanged
Low
High
None
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876. Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Jun 30, 2025 · Source: OSV.dev
CVE-2024-47220
GHSA-6f62-3596-g6w7
Sep 22, 2024
HTTP Request Smuggling in ruby webrick
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/1.1\r\n" request. NOTE: the supplier's position is "Webrick should not be used in production." Affected versions
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.6.0
1.6.1
1.7.0
+ 2 more Show less
1.8.0
1.8.1
Fixed in
1.8.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-25613
GHSA-gwfg-cqmg-cf8f
BIT-ruby-2020-25613
BIT-ruby-min-2020-25613
May 24, 2022
WEBRick vulnerable to HTTP Request/Response Smuggling
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploit this issue to bypass a reverse proxy (which also has a poor header check), which may lead to an HTTP Request Smuggling attack. Affected versions
1.6.0
1.5.0
1.3.1
1.4.0
1.4.0.beta1
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
1.5.1
1.6.1
References
Updated May 29, 2025 · Source: OSV.dev
CVE-2017-10784
GHSA-369m-2gv6-mw28
May 14, 2022
WEBrick RCE Vulnerability
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name. Affected versions
1.3.1
1.4.0.beta1
Fixed in
1.4.0
References
Updated Mar 13, 2024 · Source: OSV.dev
CVE-2009-4492
GHSA-6mq2-37j5-w6r6
Oct 24, 2017
WEBrick Improper Input Validation vulnerability
Medium
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Affected versions
1.3.1
1.4.0.beta1
Fixed in
1.4.0
References
Updated May 22, 2025 · Source: OSV.dev |