Debian Package Tracker
Register | Log in
Subscribe

starman

high-performance preforking PSGI/Plack web server

Choose email to subscribe with

general
  • source: starman (main)
  • version: 0.4017-1
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: Yadd [DMD] – CSILLAG Tamas [DMD]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.4015-1
  • oldstable: 0.4016-1
  • stable: 0.4017-1
  • testing: 0.4017-1
  • unstable: 0.4017-1
versioned links
  • 0.4015-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.4016-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.4017-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • starman
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-40560: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
Created: 2026-04-29 Last update: 2026-04-29 19:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-40560: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
Created: 2026-04-29 Last update: 2026-04-29 19:30
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-40560: Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.
Created: 2026-04-29 Last update: 2026-04-29 19:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-40560: (needs triaging) Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-29 Last update: 2026-04-29 19:30
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2026-40560: (needs triaging) Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-29 Last update: 2026-04-29 19:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2023-10-09] starman 0.4017-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-05] Accepted starman 0.4017-1 (source) into unstable (gregor herrmann)
  • [2022-09-18] starman 0.4016-1 MIGRATED to testing (Debian testing watch)
  • [2022-09-16] Accepted starman 0.4016-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2019-10-30] starman 0.4015-1 MIGRATED to testing (Debian testing watch)
  • [2019-10-27] Accepted starman 0.4015-1 (source) into unstable (Xavier Guimard)
  • [2018-11-01] starman 0.4014-3 MIGRATED to testing (Debian testing watch)
  • [2018-10-29] Accepted starman 0.4014-3 (source) into unstable (Damyan Ivanov)
  • [2018-04-21] starman 0.4014-2 MIGRATED to testing (Debian testing watch)
  • [2018-04-13] Accepted starman 0.4014-2 (source) into unstable (Xavier Guimard) (signed by: gregor herrmann)
  • [2015-07-01] starman 0.4014-1 MIGRATED to testing (Britney)
  • [2015-06-25] Accepted starman 0.4014-1 (source all) into unstable (gregor herrmann)
  • [2015-05-16] starman 0.4011-1 MIGRATED to testing (Britney)
  • [2015-05-10] Accepted starman 0.4011-1 (source all) into unstable (gregor herrmann)
  • [2014-10-21] starman 0.4010-1 MIGRATED to testing (Britney)
  • [2014-10-10] Accepted starman 0.4010-1 (source all) into unstable (gregor herrmann)
  • [2014-04-17] starman 0.4009-1 MIGRATED to testing (Debian testing watch)
  • [2014-04-11] Accepted starman 0.4009-1 (source all) (Florian Schlichting)
  • [2013-10-26] starman 0.4008-1 MIGRATED to testing (Debian testing watch)
  • [2013-10-15] Accepted starman 0.4008-1 (source all) (CSILLAG Tamas) (signed by: Florian Schlichting)
  • [2013-08-04] starman 0.3014-1 MIGRATED to testing (Debian testing watch)
  • [2013-07-24] Accepted starman 0.3014-1 (source all) (gregor herrmann)
  • [2013-05-05] starman 0.3007-1 MIGRATED to testing (Debian testing watch)
  • [2013-03-29] Accepted starman 0.3007-1 (source all) (Alessandro Ghedini)
  • [2013-02-12] Accepted starman 0.3006-1 (source all) (Alessandro Ghedini)
  • [2012-11-18] Accepted starman 0.3005-1 (source all) (Alessandro Ghedini)
  • [2012-10-08] Accepted starman 0.3003-1 (source all) (Alessandro Ghedini)
  • [2012-07-07] starman 0.3001-1 MIGRATED to testing (Debian testing watch)
  • [2012-06-26] Accepted starman 0.3001-1 (source all) (Alessandro Ghedini)
  • [2012-03-04] starman 0.3000-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.4017-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing