VDB
Sign up
CRITICAL9.1

GHSA-g9pc-8g42-g6vq

RoadRunner is at risk of HTTP Request/Response Smuggling through vulnerable dependency

Quick fix

GHSA-g9pc-8g42-g6vq — spiral/roadrunner: upgrade to the fixed version with the command below.

composer require spiral/roadrunner:^2025.1.0

Details

The net/http package dependency used by RoadRunner improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spiral/roadrunner
Introduced in: 0Fixed in: 2025.1.0
Fixcomposer require spiral/roadrunner:^2025.1.0

References