A AegiFlow
MEDIUMCVSS 6.9

GHSA-fx4f-mhw4-qm7j

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

Published
2026-08-24
Modified
2026-08-24
Sources
github-advisory

Summary

When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between `usize::MAX - 1` and `usize::MAX` inclusive) and send it, causing the server to crash (integer overflow panic in debug builds, split_to out of bounds panic in release builds). This was fixed in `vibeio-http` 0.3.2 by erroring on the chunk length if it exceeds `usize::MAX - 2` (using `checked_add()` instead of `+` operator), preventing integer overflow.

Affected packages

EcosystemPackageAffected versionsFixed versions
rustvibeio-http0.3.2

Remediation: Upgrade to 0.3.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.