CVE-2020-26281 describes a request smuggling vulnerability in async-h1, an asynchronous HTTP/1.1 parser for Rust, affecting versions prior to 2.3.0 and any web servers, including Tide applications, utilizing it behind a reverse proxy. The vulnerability arises when the server fails to read the entire body of a long request, leading async-h1 to interpret subsequent body content as a new request. With a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector and high attack complexity, potentially allowing attackers to forge headers, mislead applications, or capture other users' requests if a reverse proxy reuses connections. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:async-h1:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.