← Back

CVE-2021-38512

nvd nist
Published: Aug 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.

Affected (11)

1 product
Actix Http
1 product
Fedora
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Actix
Before 3.0.0
Version 3.0.0
Version 3.0.0 beta1
Version 3.0.0 beta2
Version 3.0.0 beta3
Version 3.0.0 beta4
Version 3.0.0 beta5
Version 3.0.0 beta6
Version 3.0.0 beta7
Version 3.0.0 beta8
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 34

Timeline

No history available yet.