CVE-2021-31402 is a CRLF injection vulnerability affecting version 4.0.0 of the Dart dio package, specifically impacting flutterchina dio. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker to inject carriage return and line feed characters if they can control the HTTP method string, potentially leading to HTTP response splitting or other malicious behavior. While no public exploits or Metasploit modules are available, and there is minimal community discussion or media coverage, the vulnerability remains a concern due to its potential for high impact on confidentiality.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 5.0.0CPE matchmatch criteria | cpe:2.3:a:flutterchina:dio:*:*:*:*:*:dart:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.