Vulnerabilities (CVE)

Filtered by vendor Hyper Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-32715 1 Hyper 1 Hyper 2021-07-22 4.3 MEDIUM 5.3 MEDIUM
hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, when it should have been rejected as illegal. This combined with an upstream HTTP proxy that doesn't parse such `Content-Length` headers, but forwards them, can result in "request smuggling" or "desync attacks". The flaw exists in all prior versions of hyper prior to 0.14.10, if built with `rustc` v1.5.0 or newer. The vulnerability is patched in hyper version 0.14.10. Two workarounds exist: One may reject requests manually that contain a plus sign prefix in the `Content-Length` header or ensure any upstream proxy handles `Content-Length` headers with a plus sign prefix.
CVE-2016-10932 2 Hyper, Microsoft 2 Hyper, Windows 2021-01-07 5.8 MEDIUM 4.8 MEDIUM
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
CVE-2018-10205 1 Hyper 1 Hyperstart 2019-10-03 5.0 MEDIUM 5.3 MEDIUM
hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker.
CVE-2017-18587 1 Hyper 1 Hyper 2019-09-03 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.