This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate actix

Dependencies

(19 total, 12 outdated, 1 insecure)

CrateRequiredLatestStatus
 actix-http ⚠️^0.2.03.18.12insecure
 actix-rt^0.2.22.15.0out of date
 actix_derive^0.40.6.2out of date
 bitflags^1.02.13.2out of date
 bytes^0.41.12.1out of date
 crossbeam-channel^0.30.5.17out of date
 derive_more^0.14.02.1.1out of date
 futures^0.1.250.3.34out of date
 hashbrown^0.3.00.17.1out of date
 lazy_static^1.21.5.0up to date
 log^0.40.4.34up to date
 parking_lot^0.80.12.5out of date
 smallvec^0.61.16.2out of date
 tokio-codec^0.10.1.2up to date
 tokio-executor^0.10.1.10up to date
 tokio-io^0.10.1.13up to date
 tokio-tcp^0.10.1.4up to date
 tokio-timer^0.2.80.2.13up to date
 trust-dns-resolver^0.11.00.23.2out of date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 doc-comment^0.30.3.4up to date

Security Vulnerabilities

actix-http: Use-after-free in BodyStream due to lack of pinning

RUSTSEC-2020-0048

Affected versions of this crate did not require the buffer wrapped in BodyStream to be pinned, but treated it as if it had a fixed location in memory. This may result in a use-after-free.

The flaw was corrected by making the trait MessageBody require Unpin and making poll_next() function accept Pin<&mut Self> instead of &mut self.

actix-http: Potential request smuggling capabilities due to lack of input validation

RUSTSEC-2021-0081

Affected versions of this crate did not properly detect invalid requests that could allow HTTP/1 request smuggling (HRS) attacks when running alongside a vulnerable front-end proxy server. This can result in leaked internal and/or user data, including credentials, when the front-end proxy is also vulnerable.

Popular front-end proxies and load balancers already mitigate HRS attacks so it is recommended that they are also kept up to date; check your specific set up. You should upgrade even if the front-end proxy receives exclusively HTTP/2 traffic and connects to the back-end using HTTP/1; several downgrade attacks are known that can also expose HRS vulnerabilities.