CVE-2025-22871
RoadRunner request smuggling via bare-LF chunk-size line (bundled Go net/http)
- Severity
- critical
- Affected product
- RoadRunner
- Affected versions
- RoadRunner < 2025.1.0
- Fixed in
- RoadRunner 2025.1.0
- Added to NewScan
- 2026-09-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints RoadRunner from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only, and it cannot fire from the X-Powered-By banner - RoadRunner publishes no version there, so this row needs a version from elsewhere (an exposed composer.lock, /vendor/composer/installed.json, or an SBOM). Inherited from the Go net/http the binary was built with, not a RoadRunner bug: the desync only works when a FRONT PROXY also treats a bare LF as a valid chunk extension, and that disagreement is not visible from the outside. So a version match means "vulnerable build", never "confirmed exploitable".
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →