vibeio-http is vulnerable to Denial of Service (DoS)
30
Low Risk
When using the affected versions of the vibeio-http crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between usize::MAX - 1 and usize::MAX inclusive) and send it, causing the server to crash (integer overflow panic in debug builds, split_to out of bounds panic in release builds).
You are affected if you are using a version that falls within the vulnerable range.
vibeio-http is vulnerable to Denial of Service (DoS) in versions 0.0.0 - 0.3.1.
Upgrade the vibeio-http library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant