<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:39:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-02054</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-02054</link>
      <description>bdu:2022-02054</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-02054</guid>
    </item>
    <item>
      <title>EUVD-2026-28056</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-28056</link>
      <description>EUVD-2026-28056</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-28056</guid>
    </item>
    <item>
      <title>fkie_cve-2021-32714</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-32714</link>
      <description>&lt;p&gt;hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks.&amp;#34; The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks.&amp;#34; The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-32714</guid>
    </item>
    <item>
      <title>GHSA-5h46-h7hh-c6x9 — Integer Overflow in Chunked Transfer-Encoding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5h46-h7hh-c6x9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: hyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks&amp;#34;.&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;```
GET / HTTP/1.1
Host: example.com
Transfer-Encoding: chunked&lt;/p&gt;
&lt;p&gt;f0000000000000003
abc
0&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;hyper only reads the rightmost 64-bit integer as the chunk size. So it reads `f0000000000000003` as `3`. A loss of data can occur since hyper would then read only 3 bytes of the body. Additionally, an HTTP request smuggling vulnerability would occur if using a proxy which instead has prefix truncation in the chunk size, or that understands larger than 64-bit chunk sizes.&lt;/p&gt;
&lt;p&gt;Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;To determine if vulnerable to _data loss_, these things must be true:&lt;/p&gt;
&lt;p&gt;- **Using HTTP/1.1.** Since HTTP/2 does not use chunked encoding, it is not vulnerable.
- **Using hyper as a server or client.** The body would be improperly truncated in either case.
- **Users send requests or responses with chunk sizes greater than 18 exabytes**.&lt;/p&gt;
&lt;p&gt;To determine if vulnerable to _desync attacks_, these things must be true:&lt;/p&gt;
&lt;p&gt;- **Using an upstream proxy that allows chunks sizes larger than 64-bit.** If the proxy rejects chunk sizes that are too large, that request…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: hyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks&amp;#34;.&lt;/p&gt;
&lt;p&gt;### Vulnerability&lt;/p&gt;
&lt;p&gt;Example:&lt;/p&gt;
&lt;p&gt;```
GET / HTTP/1.1
Host: example.com
Transfer-Encoding: chunked&lt;/p&gt;
&lt;p&gt;f0000000000000003
abc
0&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;hyper only reads the rightmost 64-bit integer as the chunk size. So it reads `f0000000000000003` as `3`. A loss of data can occur since hyper would then read only 3 bytes of the body. Additionally, an HTTP request smuggling vulnerability would occur if using a proxy which instead has prefix truncation in the chunk size, or that understands larger than 64-bit chunk sizes.&lt;/p&gt;
&lt;p&gt;Read more about desync attacks: https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;To determine if vulnerable to _data loss_, these things must be true:&lt;/p&gt;
&lt;p&gt;- **Using HTTP/1.1.** Since HTTP/2 does not use chunked encoding, it is not vulnerable.
- **Using hyper as a server or client.** The body would be improperly truncated in either case.
- **Users send requests or responses with chunk sizes greater than 18 exabytes**.&lt;/p&gt;
&lt;p&gt;To determine if vulnerable to _desync attacks_, these things must be true:&lt;/p&gt;
&lt;p&gt;- **Using an upstream proxy that allows chunks sizes larger than 64-bit.** If the proxy rejects chunk sizes that are too large, that request…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5h46-h7hh-c6x9</guid>
    </item>
    <item>
      <title>gsd-2021-32714</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-32714</link>
      <description>gsd-2021-32714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-32714</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-32714 — Integer Overflow in Chunked Transfer-Encoding</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-32714</link>
      <description>msrc_CVE-2021-32714</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-32714</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11751-1 — afterburn-5.0.0-6.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11751-1</link>
      <description>&lt;p&gt;afterburn-5.0.0-6.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;afterburn-5.0.0-6.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11751-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2021-0079 — Integer overflow in `hyper`'s parsing of the `Transfer-Encoding` header leads to data loss</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2021-0079</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: hyper&lt;/p&gt;
&lt;p&gt;When decoding chunk sizes that are too large, `hyper`&amp;#39;s code would encounter an integer overflow. Depending on the situation,
this could lead to data loss from an incorrect total size, or in rarer cases, a request smuggling attack.&lt;/p&gt;
&lt;p&gt;To be vulnerable, you must be using `hyper` for any HTTP/1 purpose, including as a client or server, and consumers must send
requests or responses that specify a chunk size greater than 18 exabytes. For a possible request smuggling attack to be possible,
any upstream proxies must accept a chunk size greater than 64 bits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: hyper&lt;/p&gt;
&lt;p&gt;When decoding chunk sizes that are too large, `hyper`&amp;#39;s code would encounter an integer overflow. Depending on the situation,
this could lead to data loss from an incorrect total size, or in rarer cases, a request smuggling attack.&lt;/p&gt;
&lt;p&gt;To be vulnerable, you must be using `hyper` for any HTTP/1 purpose, including as a client or server, and consumers must send
requests or responses that specify a chunk size greater than 18 exabytes. For a possible request smuggling attack to be possible,
any upstream proxies must accept a chunk size greater than 64 bits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2021-0079</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-32714</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32714</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-hyper&lt;/p&gt;
&lt;p&gt;hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks.&amp;#34; The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-hyper&lt;/p&gt;
&lt;p&gt;hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper&amp;#39;s HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in &amp;#34;request smuggling&amp;#34; or &amp;#34;desync attacks.&amp;#34; The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-32714</guid>
    </item>
  </channel>
</rss>
