Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79800.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-79800
Upstream
Published
2026-03-12T20:16:05Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-32240 affecting package capnproto 1.0.1-4
Details

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be truncated to a 64-bit integer. In theory, this bug could enable HTTP request/response smuggling. This vulnerability is fixed in 1.4.0.

References

Affected packages

Azure Linux:3 / capnproto

Package

Name
capnproto
Purl
pkg:rpm/azure-linux/capnproto

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.1-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79800.json"