Microsoft Security Response Center 中文 关注 CVE-2026-38969:在 v1.9.2 及之前版本中,Ruby WEBrick 会重新解析 trailer 中的 Content-Length 并将其转换为规范请求状态,从而允许请求注入攻击。 CVE-2026-38969 ruby webrick through v1.9.2 WEBrick reparses trailer Content-Length into canonical request state, enabling request smuggling. msrc.microsoft.com