{"id":"CVE-2020-7659","aliases":["GHSA-x3v4-pxvm-63j8","SNYK-RUBY-REEL-569135"],"url":"https://o3.security/vulnerability/CVE-2020-7659","summary":"HTTP Request Smuggling in reel","details":"reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were found to be parsed as valid which could be leveraged for TE:CL smuggling attacks. Note: This project is deprecated, and is not maintained any more.","published":"2020-06-01T13:15:10.313Z","modified":"2026-07-09T14:44:02.673831Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"RubyGems","name":"reel","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-RUBY-REEL-569135"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T14:44:02.673831Z"}}