hyper
A protective and efficient HTTP library for all.
Activity
- Latest release
- 2w ago
- Total releases
- 252
- Cadence
- ~32 days
- Last 12 months
- 7
Details
- License
- MIT
- First release
- Nov 22, 2014
| Version | Released | |
|---|---|---|
1.11.1
patch
|
1.11.1
patch
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
1.11.0
unknown
|
1.11.0
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
1.10.1
unknown
|
1.10.1
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
1.10.0
unknown
|
1.10.0
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
1.9.0
unknown
|
1.9.0
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
1.8.1
unknown
|
1.8.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.8.0
unknown
|
1.8.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.7.0
unknown
|
1.7.0
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.6.0
unknown
|
1.6.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.5.2
unknown
|
1.5.2
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.14.32
unknown
|
0.14.32
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.5.1
unknown
|
1.5.1
unknown
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
1.5.0
unknown
|
1.5.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.14.31
unknown
|
0.14.31
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.4.1
unknown
|
1.4.1
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.14.30
unknown
|
0.14.30
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.4.0
unknown
|
1.4.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.14.29
unknown
|
0.14.29
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.3.1
unknown
|
1.3.1
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.3.0
unknown
|
1.3.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.2.0
unknown
|
1.2.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
1.1.0
unknown
|
1.1.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.14.28
unknown
|
0.14.28
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.0.1
unknown
|
1.0.1
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
1.0.0
unknown
|
1.0.0
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
1.0.0-rc.4
unknown
|
1.0.0-rc.4
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.14.27
unknown
|
0.14.27
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.26
unknown
|
0.14.26
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.25
unknown
|
0.14.25
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.0.0-rc.3
unknown
|
1.0.0-rc.3
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
0.14.24
unknown
|
0.14.24
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.0.0-rc.2
unknown
|
1.0.0-rc.2
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
0.14.23
unknown
|
0.14.23
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.22
unknown
|
0.14.22
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.21
unknown
|
0.14.21
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.0.0-rc.1
unknown
|
1.0.0-rc.1
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.20
unknown
|
0.14.20
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.19
unknown
|
0.14.19
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.18
unknown
|
0.14.18
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.17
unknown
|
0.14.17
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.16
unknown
|
0.14.16
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.15
unknown
|
0.14.15
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.14
unknown
|
0.14.14
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
0.14.13
unknown
|
0.14.13
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
0.14.12
unknown
|
0.14.12
unknown
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
0.14.11
unknown
1 CVE
GHSA-f67m-9j94-qv9j
RUSTSEC-2022-0022
Jun 16, 2022
Parser creates invalid uninitialized value
High
Affected versions of this crate called The flaw was corrected by avoiding the use of Fixed in
0.14.12
References Updated Sep 10, 2026 · Source: OSV.dev |
0.14.11
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.14.10
unknown
1 CVE
GHSA-f67m-9j94-qv9j
RUSTSEC-2022-0022
Jun 16, 2022
Parser creates invalid uninitialized value
High
Affected versions of this crate called The flaw was corrected by avoiding the use of Fixed in
0.14.12
References Updated Sep 10, 2026 · Source: OSV.dev |
0.14.10
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.14.9
unknown
3 CVEs
GHSA-f67m-9j94-qv9j
RUSTSEC-2022-0022
Jun 16, 2022
Parser creates invalid uninitialized value
High
Affected versions of this crate called The flaw was corrected by avoiding the use of Fixed in
0.14.12
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32714
GHSA-5h46-h7hh-c6x9
RUSTSEC-2021-0079
Jul 12, 2021
Integer Overflow in Chunked Transfer-Encoding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summaryhyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks". VulnerabilityExample:
hyper only reads the rightmost 64-bit integer as the chunk size. So it reads Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable to data loss, these things must be true:
To determine if vulnerable to desync attacks, these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32715
GHSA-f3pg-qwvg-p99c
RUSTSEC-2021-0078
Jul 12, 2021
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
3.1
/ 10
Low
Network
High
None
Required
Unchanged
Low
None
None
Summaryhyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a VulnerabilityThe flaw exists in all prior versions of hyper, if built with Example:
This request gets accepted and hyper reads the body as abc. The request should be rejected, according to RFC 7230, since the ABNF for In this particular case, an upstream proxy would need to error when parsing the Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable, all these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.9
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.14.8
unknown
3 CVEs
GHSA-f67m-9j94-qv9j
RUSTSEC-2022-0022
Jun 16, 2022
Parser creates invalid uninitialized value
High
Affected versions of this crate called The flaw was corrected by avoiding the use of Fixed in
0.14.12
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32714
GHSA-5h46-h7hh-c6x9
RUSTSEC-2021-0079
Jul 12, 2021
Integer Overflow in Chunked Transfer-Encoding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summaryhyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks". VulnerabilityExample:
hyper only reads the rightmost 64-bit integer as the chunk size. So it reads Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable to data loss, these things must be true:
To determine if vulnerable to desync attacks, these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32715
GHSA-f3pg-qwvg-p99c
RUSTSEC-2021-0078
Jul 12, 2021
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
3.1
/ 10
Low
Network
High
None
Required
Unchanged
Low
None
None
Summaryhyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a VulnerabilityThe flaw exists in all prior versions of hyper, if built with Example:
This request gets accepted and hyper reads the body as abc. The request should be rejected, according to RFC 7230, since the ABNF for In this particular case, an upstream proxy would need to error when parsing the Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable, all these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.8
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
0.14.7
unknown
3 CVEs
GHSA-f67m-9j94-qv9j
RUSTSEC-2022-0022
Jun 16, 2022
Parser creates invalid uninitialized value
High
Affected versions of this crate called The flaw was corrected by avoiding the use of Fixed in
0.14.12
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32714
GHSA-5h46-h7hh-c6x9
RUSTSEC-2021-0079
Jul 12, 2021
Integer Overflow in Chunked Transfer-Encoding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
Summaryhyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks". VulnerabilityExample:
hyper only reads the rightmost 64-bit integer as the chunk size. So it reads Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable to data loss, these things must be true:
To determine if vulnerable to desync attacks, these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-32715
GHSA-f3pg-qwvg-p99c
RUSTSEC-2021-0078
Jul 12, 2021
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
3.1
/ 10
Low
Network
High
None
Required
Unchanged
Low
None
None
Summaryhyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a VulnerabilityThe flaw exists in all prior versions of hyper, if built with Example:
This request gets accepted and hyper reads the body as abc. The request should be rejected, according to RFC 7230, since the ABNF for In this particular case, an upstream proxy would need to error when parsing the Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn ImpactTo determine if vulnerable, all these things must be true:
PatchesWe have released the following patch versions:
WorkaroundsBesides upgrading hyper, you can take the following options:
CreditsThis issue was initially reported by Mattias Grenfeldt and Asta Olofsson. Fixed in
0.14.10
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.14.7
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|