actix-http
Actix Web is a powerful, pragmatic, and extremely fast web framework for Rust.
Activity
- Latest release
- 1w ago
- Total releases
- 97
- Cadence
- ~19 days
- Last 12 months
- 9
Reach
- Downloads
- 75.9M
- Stars
- 24.8k
Details
- License
- MIT OR Apache-2.0
- First release
- Mar 28, 2019
| Version | Released | |
|---|---|---|
3.13.5
patch
|
3.13.5
patch
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
3.13.4
patch
|
3.13.4
patch
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
3.13.3
patch
|
3.13.3
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.13.2
patch
|
3.13.2
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.13.1
unknown
|
3.13.1
unknown
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.13.0
unknown
|
3.13.0
unknown
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.12.1
unknown
|
3.12.1
unknown
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
3.12.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.12.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.11.2
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.11.2
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.11.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.11.1
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.11.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.11.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.10.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.10.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.9.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.9.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.8.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.8.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.7.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.7.0
unknown
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
3.6.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.6.0
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.5.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.5.1
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.5.0
unknown
yanked
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0
unknown
yanked
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.4.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.4.0
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.3.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.3.1
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.3.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.3.0
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.2.2
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.2
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.2.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.2.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.2.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.1.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.1.0
unknown
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
3.0.4
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.4
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.3
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.3
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.2
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.2
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-rc.4
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-rc.4
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-rc.3
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-rc.3
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-rc.2
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-rc.2
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-rc.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-rc.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
2.2.2
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.2
unknown
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
3.0.0-beta.19
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.19
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-beta.18
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.18
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-beta.17
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.17
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
3.0.0-beta.16
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.16
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
3.0.0-beta.15
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.15
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.0.0-beta.14
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.14
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.0.0-beta.13
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.13
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.0.0-beta.12
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.12
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
3.0.0-beta.11
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.11
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
3.0.0-beta.10
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.10
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
3.0.0-beta.9
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.9
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
2.2.1
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.1
unknown
Dependencies (41)
+ 33 more
Changelog
Compare changes
|
|
3.0.0-beta.8
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.8
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
3.0.0-beta.7
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.7
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
3.0.0-beta.6
unknown
1 CVE
CVE-2026-73051
GHSA-xhj4-vrgc-hr34
Apr 22, 2026
actix-http has HTTP/1.1 CL.TE Request Smuggling
Medium
Network
Low
None
None
A vulnerability in SeverityMedium.
This is an HTTP request smuggling vulnerability that can be triggered over the network without application-level credentials. Exploitation requires a specific proxy topology: an upstream proxy, WAF, load balancer, or similar intermediary must use Affected Versions
DescriptionHTTP/1.1 requests that contain both Affected versions of In a CL.TE proxy topology, an intermediary may treat bytes after the declared The issue is limited to HTTP/1.1 request parsing. ImpactHTTP request smuggling
No direct confidentiality, availability, or subsequent-system impact is scored for this advisory. Fixed VersionsThis issue is fixed in actix-http 3.12.1. The fix rejects HTTP/1.1 requests that contain both MitigationUsers should upgrade to actix-http 3.12.1 or later. Applications that depend on
If an immediate upgrade is not possible, configure all upstream HTTP intermediaries to reject HTTP/1.1 requests that contain both CreditsActix thanks mufeedvh who disclosed this issue through coordinated disclosure. Fixed in
3.12.1
References Updated Sep 10, 2026 · Source: OSV.dev |
3.0.0-beta.6
unknown
Dependencies (37)
+ 29 more
Changelog
Compare changes
|