What is CVE-2026-73051?
CVE-2026-73051 is an HTTP request smuggling vulnerability in actix-http versions prior to 3.12.1. The HTTP/1.1 parser accepts requests with both Content-Length and Transfer-Encoding: chunked headers, allowing unauthenticated remote attackers to desynchronize the backend via a front-end intermediary. Upgrading to version 3.12.1 or later is advised.
Azərbaycanca: CVE-2026-73051 actix-http kitabxanasının 3.12.1-dən əvvəlki versiyalarında HTTP request smuggling zəifliyidir. HTTP/1.1 parser həm Content-Length, həm də Transfer-Encoding: chunked başlıqlarını qəbul etdiyi üçün autentifikasiya olunmamış uzaqdan hücumçu front-end vasitəçi ilə backend sinxronizasiyasını poza bilər. Kitabxananı ən azı 3.12.1 versiyasına yeniləmək tövsiyə olunur.
FAQ2
Which versions of actix-http are affected by the HTTP request smuggling vulnerability?
CVE-2026-73051 affects actix-http versions prior to 3.12.1.
How can I protect against CVE-2026-73051?
Upgrading to actix-http version 3.12.1 or later is advised.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.