This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.
The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
{ "nvd_published_at": "2021-04-15T19:15:00Z", "cwe_ids": [ "CWE-74", "CWE-88", "CWE-93" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-09-15T03:27:03Z" }