Affected versions of this crate called mem::uninitialized() in the HTTP1 parser to create values of type httparse::Header (from the httparse crate).
This is unsound, since Header contains references and thus must be non-null.
The flaw was corrected by avoiding the use of mem::uninitialized(), using MaybeUninit instead.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2022-06-16T23:59:29Z",
"nvd_published_at": null,
"severity": "HIGH"
}