dio
A powerful HTTP client for Dart and Flutter, which supports global settings, Interceptors, FormData, aborting and canceling a request, files uploading and downloading, requests timeout, custom adapters, etc.
Activity
- Latest release
- 1w ago
- Total releases
- 149
- Cadence
- ~10 days
- Last 12 months
- 5
Reach
- Stars
- 12.8k
Details
- First release
- Apr 21, 2018
| Version | Released | |
|---|---|---|
5.11.1
patch
| ||
5.11.0
minor
| ||
5.10.0
minor
| ||
5.9.2
patch
| ||
5.9.1
patch
| ||
5.9.0
minor
| ||
5.8.0+1
minor
| ||
5.7.0
minor
| ||
5.6.0
minor
| ||
5.5.0+1
unknown
| ||
5.5.0
minor
| ||
5.4.3+1
unknown
| ||
5.4.3
patch
| ||
5.4.2+1
patch
| ||
5.4.1
patch
| ||
5.4.0
minor
| ||
5.3.4
patch
| ||
5.3.3
patch
| ||
5.3.2
patch
| ||
5.3.1
patch
| ||
5.3.0
minor
| ||
5.2.1+1
unknown
| ||
5.2.1
patch
| ||
5.2.0+1
unknown
| ||
5.2.0
minor
| ||
5.1.2
patch
| ||
5.1.1
patch
| ||
5.1.0
minor
| ||
5.0.3
patch
| ||
5.0.2
patch
| ||
5.0.1
patch
| ||
5.0.0
major
| ||
4.0.6
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.5
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.5-beta1
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.4
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.3
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.2
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.2-beta1
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.1
patch
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-prev3
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-prev2
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-prev1
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta7
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta6
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta5
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta4
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta3
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
4.0.0-beta2
pre
1 CVE
CVE-2021-31402
GHSA-9324-jv53-9cc8
Mar 21, 2023
dio vulnerable to CRLF injection with HTTP method string
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ImpactThe dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669. PatchesThe vulnerability has been resolved by https://github.com/cfug/dio/commit/927f79e93ba39f3c3a12c190624a55653d577984, and included since v5.0.0. WorkaroundsCherry-pick the commit to your own fork can resolves the vulberability too. References
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
+ 105 more Show less
0.0.8
0.0.9
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
2.0.0
2.0.1
2.0.10
2.0.11
2.0.12
2.0.13
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
3.0.0
3.0.0-dev.1
3.0.1
3.0.10
3.0.2
3.0.2-dev.1
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.8-dev.1
3.0.9
4.0.0
4.0.0-beta1
4.0.0-beta2
4.0.0-beta3
4.0.0-beta4
4.0.0-beta5
4.0.0-beta6
4.0.0-beta7
4.0.0-prev1
4.0.0-prev2
4.0.0-prev3
4.0.1
4.0.2
4.0.2-beta1
4.0.3
4.0.4
4.0.5
4.0.5-beta1
4.0.6
Fixed in
5.0.0
References
Updated Feb 16, 2024 · Source: OSV.dev |