GHSA-r995-q44h-hr64 · Severity: medium · Ecosystem: rubygems — Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed behind an HTTP proxy that fulfills specific conditions. The specific flaw exists within the read_headers method. The issue results from the inconsistent parsing of terminators of HTTP headers. An attacker can leverage this vulnerability to smuggle arbitrary HTTP requests. Was ZDI-CAN-21876.
Conclusion & alert: CVE-2025-6442 is rated Moderate Risk (41/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.26%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-21 | 0.06% | 0.26% | +0.20% |
| 2 | 2026-01-19 | 0.04% | 0.06% | +0.02% |
| 3 | 2025-11-21 | — | 0.04% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 6.5 | 3.0 | MEDIUM |
|
2.2 | 4.2 | [email protected] |
GHSA-r995-q44h-hr64 · Severity: medium · Ecosystem: rubygems — Ruby WEBrick read_headers method can lead to HTTP Request/Response Smuggling
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-6442: 1 source package rows (ruby-webrick); 2 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 2. | https://security.alpinelinux.org/vuln/CVE-2025-6442 |
debian
|
not yet assigned | CVE-2025-6442 not yet assigned priority: Debian including 1 source packages (ruby-webrick), 4 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 3, open 1. | https://security-tracker.debian.org/tracker/CVE-2025-6442 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-6442 |
suse
|
medium | — | https://www.suse.com/security/cve/CVE-2025-6442/ |
ubuntu
|
medium | CVE-2025-6442 medium priority: Ubuntu including 5 source packages (jruby, ruby-webrick, ruby2.3, ruby2.5, ruby2.7), 33 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 13, released 8, needed 4, needs-triage 4, not-affected 3, ignored 1. | https://ubuntu.com/security/CVE-2025-6442 |