Medium severity6.1NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2020-36202
CVE-2020-36202
Description
An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
async-h1crates.io | < 2.3.0 | 2.3.0 |
Affected products
3- Rust/async-h1 cratedescription
Patches
Vulnerability mechanics
References
4- rustsec.org/advisories/RUSTSEC-2020-0093.htmlnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-c8rq-crxj-mj9mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-36202ghsaADVISORY
- github.com/http-rs/async-h1/releases/tag/v2.3.0ghsaWEB
News mentions
0No linked articles in our index yet.