Affected versions of this crate called mem::uninitialized()
in the HTTP1 parser to create values of type httparse::Header
(from the httparse
crate).
This is unsound, since Header
contains references and thus must be non-null.
The flaw was corrected by avoiding the use of mem::uninitialized()
, using MaybeUninit
instead.
{ "nvd_published_at": null, "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-16T23:59:29Z" }