GHSA-7v2r-wxmg-mgvc
MODERATECVE-2020-35884HTTP pipelining issues and request smuggling attacks are possible due to incorrect Transfer encoding header parsing. It is possible conduct HTTP request smuggling attacks (CL:TE/TE:TE) by sending invalid Transfer Encoding headers. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
- Affected
- < 0.8.0
- Fixed in
- 0.8.0
- Weakness
- CWE-444
- Published
- 2021-08-25
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference