PT-2026-72011 · Unknown · Actix-Http
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
actix-http versions prior to 3.12.1
Description
An issue exists in the HTTP/1.1 parser that allows the processing of requests containing both
Content-Length and Transfer-Encoding: chunked headers. This can be exploited by unauthenticated remote attackers using a front-end intermediary to desynchronize backend requests, enabling the smuggling of malicious HTTP requests to the Actix service. HTTP request smuggling is a technique used to interfere with the way a website processes sequences of HTTP requests.Recommendations
Update actix-http to version 3.12.1 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Actix-Http