actix-files
Actix Web is a powerful, pragmatic, and extremely fast web framework for Rust.
Activity
- Latest release
- 3w ago
- Total releases
- 53
- Cadence
- ~22 days
- Last 12 months
- 3
Reach
- Downloads
- 11.6M
- Stars
- 24.8k
Details
- License
- MIT OR Apache-2.0
- First release
- Mar 28, 2019
| Version | Released | |
|---|---|---|
0.7.0
minor
|
0.7.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.6.10
unknown
|
0.6.10
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
0.6.9
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.9
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
0.6.8
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.8
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
0.6.7
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.7
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
0.6.6
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.6
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
0.6.5
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.5
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.6.4
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.4
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.6.2
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.2
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
0.6.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.1
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
0.6.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.16
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.16
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.15
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.15
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.14
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.14
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.13
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.13
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.12
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.12
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.11
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.11
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.10
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.10
unknown
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
0.6.0-beta.9
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.9
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.6.0-beta.8
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.8
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.0-beta.7
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.7
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.0-beta.6
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.6
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.0-beta.5
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.5
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.6.0-beta.4
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.4
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.6.0-beta.3
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.3
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.6.0-beta.2
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.2
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.6.0-beta.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0-beta.1
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.5.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.4.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.4.1
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.4.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.3.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.3.0-beta.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-beta.1
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.2.2
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.2
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.3.0-alpha.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.3.0-alpha.1
unknown
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
0.2.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.1
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.2.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.2.0-alpha.3
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0-alpha.3
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.2.0-alpha.2
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0-alpha.2
unknown
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
0.2.0-alpha.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0-alpha.1
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.7
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.7
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.6
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.6
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.5
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.5
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.4
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.4
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.3
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.3
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.2
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.2
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.1
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.1
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.1.0
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.1.0-beta.4
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0-beta.4
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.1.0-betsa.1
unknown
yanked
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0-betsa.1
unknown
yanked
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
0.1.0-alpha.6
unknown
2 CVEs
CVE-2026-72813
GHSA-gcqf-3g44-vc9p
Feb 06, 2026
[actix-files] Panic triggered by empty Range header in GET request for static file
Medium
Network
Low
None
None
SummaryA GET request for a static file served by Details
PoC
Create these files, then run This assumes a reasonably UNIX-like system with Rust, ImpactIt is believed that only programs compiled with panic = "abort" are affected significantly. The only potential impact that can be seen is Denial of Service, though an attacker able to repeatedly send GET requests without those requests getting blocked by rate limiting, DDoS protection, etc. would be able to keep a server down indefinitely. As only a single unblocked request is needed to trigger the panic, merely having a rate limiter may not be enough to prevent this. Though the impact in the worst case is significant, the real-world risk of this vulnerability appears to be limited, as it would be expected that anyone for whom uptime is a significant concern would not compile their program with panic = "abort". Fixed in
0.6.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-72814
GHSA-8v2v-wjwg-vx6r
Feb 06, 2026
actix-files has a possible exposure of information vulnerability
Medium
Network
Low
None
None
SummaryWhen passing a non-existing folder to the DetailsThe
When the This behavior causes the library to expose unexpected files when the folder is not present. PoCThere is a working PoC on https://github.com/Angelmmiguel/actix-files-vuln, although the next steps can be followed to reproduce the issue
ImpactThis is an exposure of information vulnerability. It affects anyone using the Fixed in
0.6.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0-alpha.6
unknown
Dependencies (12)
+ 4 more
Changelog
Compare changes
|