Hyper
Vendor:
First CVE: Aug 26, 2019 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hyper over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2019
6 years ago
Most Recent CVE
Apr 11, 2023
1,200 days ago
CVE Severity & Scoring
Hyper8 CVEs
38%
38%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35863CRITICAL An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on t | Dec 31, 2020 | 9.8 | 31 | NO | NO |
CVE-2021-32714CRITICAL hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes tha | Jul 7, 2021 | 9.1 | 27 | NO | NO |
CVE-2021-21299HIGH hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request sm | Feb 11, 2021 | 8.1 | 27 | NO | NO |
CVE-2023-26964HIGH An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high wh | Apr 11, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-31394HIGH Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks. | Feb 21, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-32715MEDIUM hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, when | Jul 7, 2021 | 5.3 | 19 | NO | NO |
CVE-2017-18587MEDIUM An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers. | Aug 26, 2019 | 5.3 | 18 | NO | NO |
CVE-2016-10932MEDIUM An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted. | Aug 26, 2019 | 4.8 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Hyper
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.13.7 | 1 | 7.5 | 1.1% | 0 | 0 |