{"id":"GHSA-f67m-9j94-qv9j","summary":"Parser creates invalid uninitialized value","details":"Affected versions of this crate called `mem::uninitialized()` in the HTTP1 parser to create values of type `httparse::Header` (from the `httparse` crate).\nThis is unsound, since `Header` contains references and thus must be non-null.\n \nThe flaw was corrected by avoiding the use of `mem::uninitialized()`, using `MaybeUninit` instead.\n","aliases":["RUSTSEC-2022-0022"],"modified":"2026-09-10T03:49:49.376604307Z","published":"2022-06-16T23:59:29Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-06-16T23:59:29Z"},"references":[{"type":"WEB","url":"https://github.com/hyperium/hyper/pull/2545"},{"type":"PACKAGE","url":"https://github.com/hyperium/hyper"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0022.html"}],"affected":[{"package":{"name":"hyper","ecosystem":"crates.io","purl":"pkg:cargo/hyper"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.14.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-f67m-9j94-qv9j/GHSA-f67m-9j94-qv9j.json"}}],"schema_version":"1.9.0"}