Vulnerability DatabaseGHSA-w7hm-hmxv-pvhf

GHSA-w7hm-hmxv-pvhf
Rust vulnerability analysis and mitigation

Overview

A high-severity vulnerability (GHSA-w7hm-hmxv-pvhf) was discovered in the HPACK Rust crate, affecting versions 0.3.0 and earlier. The vulnerability, disclosed on April 5, 2024, involves insufficient checking of input data in the HPACK decoder, which can lead to panics when processing certain invalid inputs. The issue specifically affects the Decoder::decode functionality in the unmaintained hpack crate (GitHub Advisory).

Technical details

The vulnerability stems from insufficient validation of buffer length when parsing integers in the update_max_dynamic_size function after encountering a SizeUpdate field. The issue has been assigned a CVSS score of 7.5 (High), with attack vector being Network, attack complexity Low, and no privileges or user interaction required. The vulnerability is tracked under CWE-754 and can be triggered with minimal input data such as [0x3f] (GitHub Advisory, GitHub Issue).

Impact

When exploited, this vulnerability leads to a denial of service condition through application panic. The CVSS metrics indicate high availability impact while maintaining unchanged scope, with no direct impact on confidentiality or integrity (GitHub Advisory).

Exploitability

The vulnerability is easily exploitable with minimal code, requiring no special privileges or user interaction. A proof of concept exists that demonstrates the issue using just a single byte of input data (GitHub Issue, RustSec Advisory).

Mitigation and workarounds

Since the original hpack crate is unmaintained, users are advised to switch to alternative implementations. A patched version has been published as hpack-patched, and alternatives such as fluke-hpack or httlib-huffman are recommended. A fix has been implemented in the patched version that properly handles the integer decoding in the update_max_dynamic_size function (GitHub Advisory, Patch Commit).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

RUSTSEC-2026-0242NONEN/A
  • Rust logoRust
  • dcrypt-api
NoYesAug 09, 2026
RUSTSEC-2026-0240NONEN/A
  • Rust logoRust
  • dcrypt-sign
NoYesAug 09, 2026
RUSTSEC-2026-0239NONEN/A
  • Rust logoRust
  • dcrypt-symmetric
NoYesAug 09, 2026
RUSTSEC-2026-0238NONEN/A
  • Rust logoRust
  • dcrypt-algorithms
NoYesAug 09, 2026
RUSTSEC-2026-0246NONEN/A
  • Rust logoRust
  • sevenz-rust
NoNoAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management