MEDIUMcrates.io

actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects

actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects

Published 6 months agoUpdated 5 days agoSource: OSV

Affected packages

  • actix-web-lab

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects | HackTribune