VYPR
Vendor

Hyperium

Products
3
CVEs
5
Across products
6
Status
Private

Products

3

Recent CVEs

5
  • CVE-2024-47609MedOct 1, 2024
    risk 0.38cvss —epss 0.01

    Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS attack that can cause the server to exit cleanly on accepting a TCP/TLS stream. This can be triggered by causing the accept call to error out…

  • CVE-2021-32714MedJul 7, 2021
    risk 0.38cvss 5.9epss 0.01

    hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that…

  • CVE-2021-21299MedFeb 11, 2021
    risk 0.25cvss 4.8epss 0.05

    hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request smuggling attack. The HTTP server code had a flaw that incorrectly understands some requests with…

  • CVE-2021-32715LowJul 7, 2021
    risk 0.13cvss 3.1epss 0.01

    hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, when it should have been rejected as illegal. This combined with an upstream HTTP proxy that doesn't…

  • CVE-2022-31394HigFeb 21, 2023
    risk 0.00cvss 7.5epss 0.01

    Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.