An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
| Software | From | Fixed in |
|---|---|---|
| actix / actix-http | 3.0.0-beta1 | 3.0.0-beta1.x |
| actix / actix-http | 3.0.0-beta2 | 3.0.0-beta2.x |
| actix / actix-http | 3.0.0-beta3 | 3.0.0-beta3.x |
| actix / actix-http | 3.0.0-beta4 | 3.0.0-beta4.x |
| actix / actix-http | 3.0.0-beta5 | 3.0.0-beta5.x |
| actix / actix-http | 3.0.0-beta6 | 3.0.0-beta6.x |
| actix / actix-http | - | 3.0.0 |
| actix / actix-http | 3.0.0 | 3.0.0.x |
| actix / actix-http | 3.0.0-beta7 | 3.0.0-beta7.x |
| actix / actix-http | 3.0.0-beta8 | 3.0.0-beta8.x |
| fedoraproject / fedora | 34 | 34.x |
actix-http
|
- | 2.2.1 |