An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-1635 An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
Github GHSA Github GHSA GHSA-8928-2fgm-6x9x HTTP Request Smuggling in actix-http
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T01:44:22.927Z

Reserved: 2021-08-10T00:00:00

Link: CVE-2021-38512

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-10T23:15:07.277

Modified: 2024-11-21T06:17:17.300

Link: CVE-2021-38512

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-06-16T00:00:00Z

Links: CVE-2021-38512 - Bugzilla

cve-icon OpenCVE Enrichment

No data.