{"id":"CVE-2026-73051","aliases":["GHSA-xhj4-vrgc-hr34"],"url":"https://o3.security/vulnerability/CVE-2026-73051","summary":"actix-http before 3.12.1 HTTP Request Smuggling via CL.TE","details":"actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.","published":"2026-08-14T11:35:45.780Z","modified":"2026-08-16T03:48:28.539051541Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"crates.io","name":"actix-http","fixedVersion":"3.12.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73051.json"},{"type":"ADVISORY","url":"https://github.com/actix/actix-web/security/advisories/GHSA-xhj4-vrgc-hr34"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73051"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/actix-http-before-http-request-smuggling-via-cl-te"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-16T03:48:28.539051541Z"}}