http is vulnerable to Double Free
65
Medium Risk
A panic-safety flaw in HeaderMap::IntoIter::drop could cause already-yielded entries stored in extra_values to be dropped twice if a value’s destructor panics while the iterator is being drained, resulting in a double-free and potential memory corruption. An attacker might exploit this by supplying or influencing values with a panic-triggering Drop implementation, then causing partial iteration so that destruction occurs in this unsafe state, which could lead to process crashes, denial of service, or in some cases undefined behavior with possible security impact.
You are affected if you are using a version that falls within the vulnerable range.
http is vulnerable to Double Free in versions 0.1.0 - 1.4.0.
Upgrade the http library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant