Bug#1142989: rust-tiny-http: CVE-2026-66752 CVE-2026-66753

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <[email protected]>
Source: rust-tiny-http
Version: 0.12.0-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for rust-tiny-http.

Filling this issue at RC level since upstream maintenance seems to
have stopped with the 0.12.0 release, is it still maintained
(upstream) should it be removed from unstable?

CVE-2026-66752[0]:
| tiny-http through 0.12.0 contains an HTTP request smuggling
| vulnerability that allows remote attackers to desynchronize request
| framing by sending a Transfer-Encoding header with any value,
| including non-chunked codings, which causes the library to
| unconditionally apply chunk-decoding and discard Content-Length.
| Attackers can exploit the discrepancy between tiny_http's improper
| Transfer-Encoding parsing and a correctly-implemented front-end
| proxy to produce two distinct interpretations of a single byte
| stream, enabling request smuggling, and can additionally send non-
| chunked bodies with non-chunked Transfer-Encoding values to cause
| failed body reads that tie up connections and consume worker threads
| without signaling errors to clients.


CVE-2026-66753[1]:
| tiny-http through 0.12.0 contains an HTTP header injection
| vulnerability that allows attackers to inject carriage return (0x0D)
| and line feed (0x0A) bytes into HTTP header values on both request
| and response sides due to insufficient validation in header parsing
| and serialization. Attackers can exploit this injection primitive to
| perform response splitting, cache poisoning, session fixation via
| Set-Cookie injection, security header override, and request
| smuggling against line-feed-tolerant backends.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66752
    https://www.cve.org/CVERecord?id=CVE-2026-66752
    https://github.com/tiny-http/tiny-http/issues/287
[1] https://security-tracker.debian.org/tracker/CVE-2026-66753
    https://www.cve.org/CVERecord?id=CVE-2026-66753
    https://github.com/tiny-http/tiny-http/issues/288

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.