VDB
Sign up
MEDIUM6.5

GHSA-7v2r-wxmg-mgvc

HTTP Request smuggling in tiny_http

Details

HTTP pipelining issues and request smuggling attacks are possible due to incorrect Transfer encoding header parsing. It is possible conduct HTTP request smuggling attacks (CL:TE/TE:TE) by sending invalid Transfer Encoding headers. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/tiny_http
Introduced in: 0Fixed in: 0.8.0

Upgrade tiny_http to 0.8.0 or newer (ecosystem crates.io).

References