This advisory has been withdrawn because it is a duplicate of GHSA-9324-jv53-9cc8. This link is maintained to preserve external references.
The dio package prior to 5.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulnerability than CVE-2020-35669.
{
"nvd_published_at": "2021-04-15T19:15:00Z",
"severity": "HIGH",
"github_reviewed_at": "2022-09-15T03:27:03Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-74",
"CWE-88",
"CWE-93"
]
}