Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Actix Web CRITICAL 9.8
CVE-2018-25025

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.

Fix: 0.7.15+
Fix from $2,300 2021-12-27
Actix Web CRITICAL 9.8
CVE-2018-25026

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between thre…

Fix: 0.7.15+
Fix from $2,300 2021-12-27
Actix Web CRITICAL 9.8
CVE-2018-25024

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leadi…

Fix: 0.7.15+
Fix from $2,300 2021-12-27
Actix Http HIGH 7.5
CVE-2021-38512

An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to cr…

Fix: 3.0.0+
Fix from $1,950 2021-08-10
Actix Codec CRITICAL 9.8
CVE-2020-35902

An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.

Fix: after 0.2.0
Fix from $2,300 2020-12-31
Actix Utils CRITICAL 9.1
CVE-2020-35898

An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to t…

Fix: 2.0.0+
Fix from $2,300 2020-12-31
Actix Http HIGH 7.5
CVE-2020-35901

An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.

Fix: after 1.0.1
Fix from $1,950 2020-12-31
Actix Service MEDIUM 5.5
CVE-2020-35899

An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to…

Fix: 1.0.6+
Fix from $1,600 2020-12-31