Source: rust-tiny-http
Version: 0.12.0-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for rust-tiny-http.

Filling this issue at RC level since upstream maintenance seems to
have stopped with the 0.12.0 release, is it still maintained
(upstream) should it be removed from unstable?

CVE-2026-66752[0]:
| tiny-http through 0.12.0 contains an HTTP request smuggling
| vulnerability that allows remote attackers to desynchronize request
| framing by sending a Transfer-Encoding header with any value,
| including non-chunked codings, which causes the library to
| unconditionally apply chunk-decoding and discard Content-Length.
| Attackers can exploit the discrepancy between tiny_http's improper
| Transfer-Encoding parsing and a correctly-implemented front-end
| proxy to produce two distinct interpretations of a single byte
| stream, enabling request smuggling, and can additionally send non-
| chunked bodies with non-chunked Transfer-Encoding values to cause
| failed body reads that tie up connections and consume worker threads
| without signaling errors to clients.


CVE-2026-66753[1]:
| tiny-http through 0.12.0 contains an HTTP header injection
| vulnerability that allows attackers to inject carriage return (0x0D)
| and line feed (0x0A) bytes into HTTP header values on both request
| and response sides due to insufficient validation in header parsing
| and serialization. Attackers can exploit this injection primitive to
| perform response splitting, cache poisoning, session fixation via
| Set-Cookie injection, security header override, and request
| smuggling against line-feed-tolerant backends.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66752
    https://www.cve.org/CVERecord?id=CVE-2026-66752
    https://github.com/tiny-http/tiny-http/issues/287
[1] https://security-tracker.debian.org/tracker/CVE-2026-66753
    https://www.cve.org/CVERecord?id=CVE-2026-66753
    https://github.com/tiny-http/tiny-http/issues/288

Regards,
Salvatore

Reply via email to