Source: rust-tiny-http Version: 0.12.0-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for rust-tiny-http. Filling this issue at RC level since upstream maintenance seems to have stopped with the 0.12.0 release, is it still maintained (upstream) should it be removed from unstable? CVE-2026-66752[0]: | tiny-http through 0.12.0 contains an HTTP request smuggling | vulnerability that allows remote attackers to desynchronize request | framing by sending a Transfer-Encoding header with any value, | including non-chunked codings, which causes the library to | unconditionally apply chunk-decoding and discard Content-Length. | Attackers can exploit the discrepancy between tiny_http's improper | Transfer-Encoding parsing and a correctly-implemented front-end | proxy to produce two distinct interpretations of a single byte | stream, enabling request smuggling, and can additionally send non- | chunked bodies with non-chunked Transfer-Encoding values to cause | failed body reads that tie up connections and consume worker threads | without signaling errors to clients. CVE-2026-66753[1]: | tiny-http through 0.12.0 contains an HTTP header injection | vulnerability that allows attackers to inject carriage return (0x0D) | and line feed (0x0A) bytes into HTTP header values on both request | and response sides due to insufficient validation in header parsing | and serialization. Attackers can exploit this injection primitive to | perform response splitting, cache poisoning, session fixation via | Set-Cookie injection, security header override, and request | smuggling against line-feed-tolerant backends. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-66752 https://www.cve.org/CVERecord?id=CVE-2026-66752 https://github.com/tiny-http/tiny-http/issues/287 [1] https://security-tracker.debian.org/tracker/CVE-2026-66753 https://www.cve.org/CVERecord?id=CVE-2026-66753 https://github.com/tiny-http/tiny-http/issues/288 Regards, Salvatore

