actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service. | |
| Title | actix-http before 3.12.1 HTTP Request Smuggling via CL.TE | |
| First Time appeared |
Actix
Actix actix-web |
|
| Weaknesses | CWE-444 | |
| CPEs | cpe:2.3:a:actix:actix-web:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Actix
Actix actix-web |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:45.780Z
Reserved: 2026-08-10T19:10:18.100Z
Link: CVE-2026-73051
No data.
Status : Received
Published: 2026-08-14T12:16:47.820
Modified: 2026-08-14T12:16:47.820
Link: CVE-2026-73051
No data.
OpenCVE Enrichment
Updated: 2026-08-14T13:15:17Z
Weaknesses