CVE-2020-35863

CRITICAL

hyper < 0.12.34 - HTTP Request Smuggling

Title source: llm
STIX 2.1

Description

An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://rustsec.org/advisories/RUSTSEC-2020-0008.html

Scores

CVSS v3 9.8
EPSS 0.0277
EPSS Percentile 84.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-444
Status published
Products (2)
crates.io/hyper 0.11.0 - 0.12.34crates.io
hyper/hyper < 0.12.34
Published Dec 31, 2020
Tracked Since Feb 18, 2026