Description
actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service. | |
| Title | actix-http before 3.12.1 HTTP Request Smuggling via CL.TE | |
| First Time appeared |
Actix
Actix actix-web |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:actix:actix-web:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Actix
Actix actix-web |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:45.780Z
Reserved: 2026-08-10T19:10:18.100Z
Link: CVE-2026-73051
No data.
Status : Received
Published: 2026-08-14T12:16:47.820
Modified: 2026-08-14T12:16:47.820
Link: CVE-2026-73051
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')