CVE-2021-32714: Integer Overflow in Chunked Transfer-Encoding

Published Jul 7, 2021
·
Updated

hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks." The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a Transfer-Encoding header or ensure any upstream proxy rejects Transfer-Encoding chunk sizes greater than what fits in 64-bit unsigned integers.

Other sources

Integer Overflow in Chunked Transfer-Encoding

Microsoft

Affected Software

3 affected componentsFixes available
hyper Hyper Rust<0.14.10
Microsoft azl3 rpm-ostree 2024.4-1
Microsoft azl3 rpm-ostree 2022.1-7

Event History

Jul 7, 2021
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Sep 11, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2021-32714?

CVE-2021-32714 is considered to have a moderate severity level due to the potential for data loss.

2

How do I fix CVE-2021-32714?

To fix CVE-2021-32714, upgrade hyper to version 0.14.10 or later.

3

What versions of hyper are affected by CVE-2021-32714?

CVE-2021-32714 affects hyper versions prior to 0.14.10.

4

What issues does CVE-2021-32714 cause?

CVE-2021-32714 can lead to integer overflow and potential data loss when decoding large chunk sizes.

5

Is there a workaround for CVE-2021-32714?

There is no documented workaround for CVE-2021-32714 other than updating to the patched version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203