Skip to content

Vulnerability in rivet project #3935

@ankitdn

Description

@ankitdn

while working in rivet project, I found a vulnerability in the h3 package caused by a case-sensitive check for the Transfer-Encoding: chunked header. By sending a mixed-case header (e.g., ChunKed), an attacker can desynchronize requests behind TCP/load balancers, potentially leading to request smuggling and unauthorized request handling.

CVE Report
CVE Link

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions