{"id":"CVE-2021-38512","details":"An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.","aliases":["GHSA-8928-2fgm-6x9x","RUSTSEC-2021-0081"],"modified":"2026-07-08T05:57:17.690920039Z","published":"2021-08-10T23:15:07.277Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:actix:actix-http:3.0.0:beta1:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta2:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta3:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta4:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta5:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta6:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta7:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:beta8:*:*:*:rust:*:*"],"extracted_events":[{"introduced":"3.0.0-beta1"},{"last_affected":"3.0.0-beta1"},{"introduced":"3.0.0-beta2"},{"last_affected":"3.0.0-beta2"},{"introduced":"3.0.0-beta3"},{"last_affected":"3.0.0-beta3"},{"introduced":"3.0.0-beta4"},{"last_affected":"3.0.0-beta4"},{"introduced":"3.0.0-beta5"},{"last_affected":"3.0.0-beta5"},{"introduced":"3.0.0-beta6"},{"last_affected":"3.0.0-beta6"},{"introduced":"3.0.0-beta7"},{"last_affected":"3.0.0-beta7"},{"introduced":"3.0.0-beta8"},{"last_affected":"3.0.0-beta8"}],"source":"CPE_STRING","vendor_product":"actix:actix-http"},{"extracted_events":[{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/67URRW4K47SR6LNQB4YALPLGGQMQK7HO/"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2021-0081.html"},{"type":"EVIDENCE","url":"https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/actix-http/RUSTSEC-2021-0081.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/actix/actix-web","events":[{"introduced":"0"},{"fixed":"64a2c13cdfed3616bf6f3ac2c39a5e1b40bfada4"},{"introduced":"64a2c13cdfed3616bf6f3ac2c39a5e1b40bfada4"},{"last_affected":"64a2c13cdfed3616bf6f3ac2c39a5e1b40bfada4"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:actix:actix-http:*:*:*:*:*:rust:*:*","cpe:2.3:a:actix:actix-http:3.0.0:-:*:*:*:rust:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"3.0.0"},{"introduced":"3.0.0-NA"},{"last_affected":"3.0.0-NA"}]}}],"versions":["3.0.0-NA","web-v3.0.0","multipart-v0.3.0","http-v2.0.0","http-test-v2.0.0","files-v0.3.0","codegen-v0.3.0","awc-v2.0.0","actors-v3.0.0","multipart-v0.3.0-beta.2","actors-v3.0.0-beta.2","web-v3.0.0-beta.4","http-v2.0.0-beta.4","awc-v2.0.0-beta.4","web-v3.0.0-beta.3","awc-v2.0.0-beta.3","web-v3.0.0-beta.2","http-v2.0.0-beta.3","http-v2.0.0-beta.2","awc-v2.0.0-beta.2","awc","multipart-v0.3.0-beta.1","files-v0.3.0-beta.1","actors-v3.0.0-beta.1","web-v3.0.0-beta.1","codegen-v0.3.0-beta.1","awc-v2.0.0-beta.1","http-v2.0.0-beta.1","files-v0.3.0-alpha.1","codegen-v0.2.2","http-test-v2.0.0-alpha.1","web-v3.0.0-alpha.3","awc-v2.0.0-alpha.2","http-v2.0.0-alpha.4","web-v3.0.0-alpha.2","actors-v3.0.0-alpha.1","http-v2.0.0-alpha.3","web-v3.0.0-alpha.1","awc-v2.0.0-alpha.1","http-v2.0.0-alpha.2","http-v2.0.0-alpha.1","codegen-v0.2.1","identity-v0.2.1","web-v2.0.0","framed-v0.3.0","files-v0.2.1","session-v0.3.0","multipart-v0.2.0","identity-v0.2.0","files-v0.2.0","cors-v0.2.0","actors-v2.0.0","web-v2.0.0-rc","http-v1.0.1","awc-v1.0.1","http-test-v1.0.0","http-v1.0.0","awc-v1.0.0","actors-v1.0.3","v2.0.0-alpha.3","v2.0.0-alpha.1","web-v1.0.9","awc-v0.2.8","files-v0.1.7","http-v0.2.11","codegen-v0.1.3","files-v0.1.6","files-v0.1.5","web-v1.0.8","awc-v0.2.7","http-test-v0.2.5","multipart-v0.1.4","awc-v0.2.6","awc-v0.2.5","http-v0.2.10","web-v1.0.7","web-v1.0.6","multipart-v0.1.3","awc-v0.2.4","http-v0.2.9","awc-v0.2.3","http-v0.2.8","files-v0.1.4","actors-v1.0.2","framed-v0.2.1","web-v1.0.5","http-v0.2.7","web-v1.0.4","http-v0.2.6","http-test-v0.2.3","session-v0.2.0","awc-v0.2.2","web-v1.0.3","http-v0.2.5","files-v0.1.3","actors-v1.0.1","web-v1.0.2","web-v1.0.1","http-test-v0.2.2","http-v0.2.4","cors-v0.1.0","files-v0.1.2","identity-v0.1.0","web-v1.0.0","http-test-v0.2.1","awc-v0.2.1","codegen-v0.1.2","session-v0.1.1","files-v0.1.1","http-v0.2.3","multipart-v0.1.2","codegen-v0.1.1","actors-v1.0.0","http-v0.2.2","multipart-v0.1.1","http-v0.2.1","files-v0.1.0","session-v0.1.0","multipart-v0.1.0","web-v1.0.0-rc","codegen-v0.1.0","web-v1.0.0-beta.4","framed-v0.2.0","awc-v0.2.0","http-v0.2.0","web-v1.0.0-beta.3","http-v0.1.5","session-v0.1.0-beta.2","web-v1.0.0-beta.2","http-v0.1.4","http-test-v0.1.1","http-v0.1.3","http-v0.1.2","multipart-v0.1.0-beta.1","v1.0.0-beta.1","awc-v0.1.1","http-v0.1.1","framed-v0.1.0","http-test-v0.1.0","awc-v0.1.0","http-v0.1.0","v1.0.0-alpha.6","v1.0.0-alpha.5","v1.0.0-alpha.4","v1.0.0-alpha.3","v1.0.0-alpha.2","http-v0.1.0-alpha.1","0.7.18","0.7.17","0.7.16","0.7.15","v0.7.14","v0.7.13","v0.7.12","v0.7.11","v0.7.10","v0.7.9","v0.7.8","v0.7.7","v0.7.6","v0.7.5","v0.7.4","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.10","v0.6.9","v0.6.8","v0.6.7","v0.6.6","v0.6.5","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.6.0","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0","v0.4.10","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.1","v0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-38512.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}