๐Ÿ” CVE Alert

CVE-2026-73051

UNKNOWN 0.0

actix-http before 3.12.1 HTTP Request Smuggling via CL.TE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.

CWE CWE-444
Vendor actix
Product actix-web
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for actix actix-web

Be the first to know when new unknown vulnerabilities affecting actix actix-web are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

actix / actix-web
0 < 3.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/actix/actix-web/security/advisories/GHSA-xhj4-vrgc-hr34 vulncheck.com: https://www.vulncheck.com/advisories/actix-http-before-http-request-smuggling-via-cl-te

Credits

๐Ÿ” mufeedvh