pub-2024-0001

HIGH CVSS 7.5 osv_pub
Description

The Dart http package is vulnerable to HTTP request smuggling via malformed headers.

Timeline
Published
2024-03-28 10:00 UTC
Last Modified
2024-04-05
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 7.5 HIGH
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 7.5,
  "datePublished": "2024-03-28T10:00:00Z",
  "dateUpdated": "2024-04-05T18:00:00Z",
  "description": "The Dart http package is vulnerable to HTTP request smuggling via malformed headers.",
  "id": "PUB-2024-0001",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 7.5,
          "baseSeverity": "HIGH",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "HIGH",
  "source": "osv_pub",
  "title": "Pub: Dart http Package Request Smuggling"
}
View JSON API Download JSON