An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHyper Http
APPHyper< 0.1.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-25574HIGH7.5same product
An issue was discovered in the http crate before 0.1.20 for Rust. An integer overflow in HeaderMap::reserve() ...
CVE-2020-35863CRITICAL9.8PL ✓same vendor
HTTP request smuggling i RCE w bibliotece hyper dla Rust
CVE-2023-26964HIGH7.5same vendor
An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP...
CVE-2022-31394HIGH7.5same vendor
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 th...
CVE-2018-9862HIGH7.8same vendor
util.c in runV 1.0.0 for Docker mishandles a numeric username, which allows attackers to obtain root access by...