actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the pr…
Info
Summary
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/actix/actix-web/security/advisories/GHSA-gcqf-3g44-vc9p
- https://www.vulncheck.com/advisories/actix-files-before-denial-of-service-via-empty-range-header
Timeline
- nvd_ingest NVD