Inconsistent interpretation of HTTP requests in hyper - CVE-2021-21299
Published: February 5, 2021 / Updated: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper interpretation of HTTP headers in transfer-encoding header processing when handling requests with multiple transfer-encoding headers. A remote attacker can send a specially crafted request to cause a denial of service.