CVE-2020-36202: Async-h1 request smuggling possible with long unread bodies
(updated )
An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy.
References
Detect and mitigate CVE-2020-36202 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →