Skip to main content

Vendor/product archive

hyper / hyper CVEs

Beta · best-effort

8 CVEs tagged to hyper / hyper1 Critical, 2 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2023-26964

Published Apr 11, 2023

An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31394

Published Feb 21, 2023

Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32715

Published Jul 7, 2021

hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, whe…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-32714

Published Jul 7, 2021

hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes th…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21299

Published Feb 11, 2021

hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a request s…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35863

Published Dec 31, 2020

An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18587

Published Aug 26, 2019

An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10932

Published Aug 26, 2019

An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1