CVE-2020-35863
Flaw in hyper allows request smuggling by sending a body in GET requests
9.8
CRITICAL
CVSS 3.1
EPSS 2.8%
Description
An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.
How to fix CVE-2020-35863
To remediate CVE-2020-35863, upgrade the affected package to a fixed version below.
- Debian/rust-hyper—upgrade to 0.12.35-1 or later
- —upgrade to 0.12.34 or later
- —upgrade to 0.12.34 or later
Is CVE-2020-35863 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 0.12.35-1
- >= 0.11.0, < 0.12.34
- >= 0.11.0, < 0.12.34
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |