CVE-2020-35863

CRITICAL

Hyper < 0.12.34 - HTTP Request Smuggling

Title source: rule
STIX 2.1

Description

An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.

Scores

CVSS v3 9.8
EPSS 0.0201
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-444
Status published
Products (2)
crates.io/hyper 0.11.0 - 0.12.34crates.io
hyper/hyper < 0.12.34
Published Dec 31, 2020
Tracked Since Feb 18, 2026