ActixCVEs & Vulnerabilities

8 CVEs affecting Actix products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

actix-http 3actix-web 3actix-codec 1actix-service 1actix-utils 1
CVE-2018-25026CRITICAL

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption.

27 Dec 2021
9.8
CVSS
CVE-2018-25025CRITICAL

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.

27 Dec 2021
9.8
CVSS
CVE-2018-25024CRITICAL

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leading to memory corruption.

27 Dec 2021
9.8
CVSS
CVE-2021-38512HIGH

An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.

11 Aug 2021
7.5
CVSS
CVE-2020-35902CRITICAL

An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.

31 Dec 2020
9.8
CVSS
CVE-2020-35901HIGH

An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.

31 Dec 2020
7.5
CVSS
CVE-2020-35899MEDIUM

An issue was discovered in the actix-service crate before 1.0.6 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.

31 Dec 2020
5.5
CVSS
CVE-2020-35898CRITICAL

An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data.

31 Dec 2020
9.1
CVSS
← PrevPage 1 / 1Next →