> USN-8650-1: Cap'n Proto vulnerabilities
[DATE: 19/08/2026 16:00]
[LANGUAGE: EN]
Chanho Kim and Jihyeok Han discovered that Cap'n Proto incorrectly
handled negative Content-Length values or excessively large chunk sizes
when processing HTTP messages. An attacker could possibly use these
issues to cause HTTP messages to be interpreted inconsistently,
resulting in HTTP request or response smuggling. (CVE-2026-32239,
CVE-2026-32240)