http-types is vulnerable to Use of Unmaintained Third Party Components
50
Medium Risk
Authorization::value uses HeaderValue::value with the claim that the internal string is ASCII, but Authorization::new and Authorization::set_credentials accept arbitrary String credentials without validation. As a result, safe code can construct a header value containing non-ASCII UTF-8 while the implementation assumes ASCII. The http-types package is no longer maintained.
You are affected if you are using this package.
http-types is vulnerable to Use of Unmaintained Third Party Components in all versions.
Remove any http-types package from your application.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant