VDB
Sign up
HIGH

GHSA-f67m-9j94-qv9j

Parser creates invalid uninitialized value

Details

Affected versions of this crate called `mem::uninitialized()` in the HTTP1 parser to create values of type `httparse::Header` (from the `httparse` crate). This is unsound, since `Header` contains references and thus must be non-null. The flaw was corrected by avoiding the use of `mem::uninitialized()`, using `MaybeUninit` instead.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/hyper
Introduced in: 0Fixed in: 0.14.12

Upgrade hyper to 0.14.12 or newer (ecosystem crates.io).

References