Ad

CVE-2026-32881

MEDIUM CVSS 3.1: 5.3 EPSS 0.06%
Updated Mar 23, 2026
Vshakitskiy
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 3.0.5
Fixed In 3.0.5
Type CWE-183
Vendor Vshakitskiy
Public PoC No

ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypass or spoofed proxy-trust headers. Chunked transfer encoding trailer handling merges declared trailer fields into req.headers after body parsing, but the denylist only blocks 9 header names.

A malicious client can exploit this by declaring these headers in the Trailer field and appending them after the final chunk, causing request.set_header to overwrite legitimate values (e.g., those set by a reverse proxy). This enables attackers to forge authentication credentials, hijack sessions, bypass IP-based rate limiting, or spoof proxy-trust headers in any downstream middleware that reads headers after ewe.read_body is called. This issue has been fixed in version 3.0.5.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Vshakitskiy Ewe
cpe:2.3:a:vshakitskiy:ewe:*:*:*:*:*:*:*:*
3.0.5