High severity7.5NVD Advisory· Published Aug 10, 2021· Updated Jun 17, 2026
CVE-2021-38512
CVE-2021-38512
Description
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
actix-httpcrates.io | < 2.2.1 | 2.2.1 |
Affected products
13cpe:2.3:a:actix:actix-http:*:*:*:*:*:rust:*:*+ 9 more
- cpe:2.3:a:actix:actix-http:*:*:*:*:*:rust:*:*range: <3.0.0
- cpe:2.3:a:actix:actix-http:3.0.0:-:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta1:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta2:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta3:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta4:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta5:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta6:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta7:*:*:*:rust:*:*
- cpe:2.3:a:actix:actix-http:3.0.0:beta8:*:*:*:rust:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- Rust/actix-httpdescription
Patches
Vulnerability mechanics
References
8- raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-http/RUSTSEC-2021-0081.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8928-2fgm-6x9xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-38512ghsaADVISORY
- rustsec.org/advisories/RUSTSEC-2021-0081.htmlnvdThird Party AdvisoryWEB
- github.com/actix/actix-web/commit/e965d8298f421e9c89fe98b1300b8361e948c324ghsaWEB
- github.com/actix/actix-web/pull/2363ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/67URRW4K47SR6LNQB4YALPLGGQMQK7HOghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67URRW4K47SR6LNQB4YALPLGGQMQK7HO/nvd
News mentions
0No linked articles in our index yet.