THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fx4f-mhw4-qm7j (medium) — vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

[GHSA] GHSA-fx4f-mhw4-qm7j (medium) — vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

medgithub_advisoriesPublished 2026-08-24

GHSA-fx4f-mhw4-qm7j Severity: medium CVE: None

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between `usize::MAX - 1` and `usize::MAX` inclusive) and send it, causing the server to cra

Original source: https://github.com/advisories/GHSA-fx4f-mhw4-qm7j