Actix

Actix-web

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 14.08.2026 11:35:45
  • Zuletzt bearbeitet 24.09.2026 20:02:50

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through ...

  • EPSS 0.39%
  • Veröffentlicht 14.08.2026 11:35:26
  • Zuletzt bearbeitet 24.09.2026 20:02:50

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an em...

  • EPSS 0.38%
  • Veröffentlicht 14.08.2026 11:35:26
  • Zuletzt bearbeitet 24.09.2026 20:02:50

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then join...

  • EPSS 1.29%
  • Veröffentlicht 27.12.2021 00:15:08
  • Zuletzt bearbeitet 21.11.2024 04:03:23

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.

  • EPSS 1.32%
  • Veröffentlicht 27.12.2021 00:15:08
  • Zuletzt bearbeitet 21.11.2024 04:03:23

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption.

  • EPSS 1.29%
  • Veröffentlicht 27.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 04:03:22

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leading to memory corruption.