VYPR
Medium severity6.5NVD Advisory· Published Dec 31, 2020· Updated Jun 17, 2026

CVE-2020-35884

CVE-2020-35884

Description

An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tiny_httpcrates.io
< 0.8.00.8.0

Affected products

4
  • ghsa-coords
    Range: < 0.8.0
  • cpe:2.3:a:tiny-http_project:tiny-http:*:*:*:*:*:rust:*:*
    Range: <=0.7.0
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.