http
Activity
- Latest release
- 1mo ago
- Total releases
- 45
- Cadence
- ~2 months
- Last 12 months
- 4
Details
- License
- MIT OR Apache-2.0
- First release
- Nov 20, 2014
| Version | Released | |
|---|---|---|
1.5.0
unknown
|
1.5.0
unknown
Dependencies (7)
|
|
1.4.2
unknown
|
1.4.2
unknown
Dependencies (7)
|
|
1.4.1
unknown
|
1.4.1
unknown
Dependencies (7)
|
|
1.4.0
unknown
|
1.4.0
unknown
Dependencies (7)
|
|
1.3.1
unknown
|
1.3.1
unknown
Dependencies (8)
|
|
1.3.0
unknown
|
1.3.0
unknown
Dependencies (8)
|
|
1.2.0
unknown
|
1.2.0
unknown
Dependencies (8)
|
|
1.1.0
unknown
|
1.1.0
unknown
Dependencies (8)
|
|
0.2.12
unknown
|
0.2.12
unknown
Dependencies (10)
+ 2 more |
|
1.0.0
unknown
|
1.0.0
unknown
Dependencies (10)
+ 2 more |
|
0.2.11
unknown
|
0.2.11
unknown
Dependencies (10)
+ 2 more |
|
0.2.10
unknown
|
0.2.10
unknown
Dependencies (10)
+ 2 more |
|
0.2.9
unknown
|
0.2.9
unknown
Dependencies (10)
+ 2 more |
|
0.2.8
unknown
|
0.2.8
unknown
Dependencies (11)
+ 3 more |
|
0.2.7
unknown
|
0.2.7
unknown
Dependencies (10)
+ 2 more |
|
0.2.6
unknown
|
0.2.6
unknown
Dependencies (10)
+ 2 more |
|
0.2.5
unknown
|
0.2.5
unknown
Dependencies (10)
+ 2 more |
|
0.2.4
unknown
|
0.2.4
unknown
Dependencies (10)
+ 2 more |
|
0.2.3
unknown
|
0.2.3
unknown
Dependencies (10)
+ 2 more |
|
0.2.2
unknown
|
0.2.2
unknown
Dependencies (10)
+ 2 more |
|
0.2.1
unknown
|
0.2.1
unknown
Dependencies (10)
+ 2 more |
|
0.2.0
unknown
|
0.2.0
unknown
Dependencies (10)
+ 2 more |
|
0.1.21
unknown
|
0.1.21
unknown
Dependencies (10)
+ 2 more |
|
0.1.20
unknown
|
0.1.20
unknown
Dependencies (10)
+ 2 more |
|
0.1.19
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.19
unknown
Dependencies (10)
+ 2 more |
|
0.1.18
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.18
unknown
Dependencies (10)
+ 2 more |
|
0.1.17
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.17
unknown
Dependencies (9)
+ 1 more |
|
0.1.16
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.16
unknown
Dependencies (9)
+ 1 more |
|
0.1.15
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.15
unknown
Dependencies (9)
+ 1 more |
|
0.1.14
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.14
unknown
Dependencies (9)
+ 1 more |
|
0.1.13
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.13
unknown
Dependencies (9)
+ 1 more |
|
0.1.12
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.12
unknown
Dependencies (9)
+ 1 more |
|
0.1.11
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.11
unknown
Dependencies (9)
+ 1 more |
|
0.1.10
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.10
unknown
Dependencies (9)
+ 1 more |
|
0.1.9
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.9
unknown
Dependencies (9)
+ 1 more |
|
0.1.8
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.8
unknown
Dependencies (9)
+ 1 more |
|
0.1.7
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.7
unknown
Dependencies (9)
+ 1 more |
|
0.1.6
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.6
unknown
Dependencies (8)
|
|
0.1.5
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.5
unknown
Dependencies (8)
|
|
0.1.4
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.4
unknown
Dependencies (8)
|
|
0.1.3
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.3
unknown
Dependencies (8)
|
|
0.1.2
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.2
unknown
Dependencies (8)
|
|
0.1.1
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.1
unknown
Dependencies (8)
|
|
0.1.0
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (8)
|
|
0.0.0-prealpha
unknown
2 CVEs
CVE-2019-25008
GHSA-x7vr-c387-8w57
CVE-2020-25574
GHSA-xvc9-xwgj-4cq9
RUSTSEC-2019-0033
Aug 25, 2021
Integer Overflow/Infinite Loop in the http crate
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
HeaderMap::reserve() used usize::next_power_of_two() to calculate the increased capacity. However, next_power_of_two() silently overflows to 0 if given a sufficiently large number in release mode. If the map was not empty when the overflow happens, the library will invoke self.grow(0) and start infinite probing. This allows an attacker who controls the argument to reserve() to cause a potential denial of service (DoS). The flaw was corrected in 0.1.20 release of http crate. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-25009
GHSA-6rhx-hqxm-8p36
RUSTSEC-2019-0034
Aug 25, 2021
Double free in http
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness. Fixed in
0.1.20
References Updated Sep 10, 2026 · Source: OSV.dev |
0.0.0-prealpha
unknown
|