CVE Explorer
CVE-2025-6442
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions.
The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HT
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"WEBrick","vendor":"Ruby","versions":[{"status":"affected","version":"1.8.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0bc93e18d7681dc51d7ed8422dea4093547976e0e27e1f310fd2ef67f6dcf609 · sha256:02ca16555dfe41f9… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0bc93e18d7681dc51d7ed8422dea4093547976e0e27e1f310fd2ef67f6dcf609 · sha256:02ca16555dfe41f9… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-444","description":"CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0bc93e18d7681dc51d7ed8422dea4093547976e0e27e1f310fd2ef67f6dcf609 · sha256:02ca16555dfe41f9… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"vendor-provided URL","tags":["vendor-advisory"],"url":"https://github.com/ruby/webrick/commit/ee60354bcb84ec33b9245e1d1aa6e1f7e8132101#diff-ad02984d873efb089aa51551bc6b7d307a53e0ba1ac439e91d69c2e58a478864"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0bc93e18d7681dc51d7ed8422dea4093547976e0e27e1f310fd2ef67f6dcf609 · sha256:02ca16555dfe41f9… · /containers/cna/references/1
{"name":"ZDI-25-414","tags":["x_research-advisory"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-414/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0bc93e18d7681dc51d7ed8422dea4093547976e0e27e1f310fd2ef67f6dcf609 · sha256:02ca16555dfe41f9… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.