CVE-2026-73051: actix-http before 3.12.1 HTTP Request Smuggling via CL.TE
actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and smuggle malicious HTTP requests to the Actix service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
actix-httpto a version that resolves this vulnerability.Fixed in 3.12.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73051?
CVE-2026-73051 has a risk rating of 71, indicating a high severity vulnerability.
How do I fix CVE-2026-73051?
To mitigate CVE-2026-73051, upgrade actix-http to version 3.12.1 or later.
What types of attacks can exploit CVE-2026-73051?
CVE-2026-73051 can be exploited by unauthenticated remote attackers using HTTP request smuggling techniques.
Which software is affected by CVE-2026-73051?
CVE-2026-73051 affects actix-http versions prior to 3.12.1.
When was CVE-2026-73051 published?
CVE-2026-73051 was published on August 14, 2026.