{
    "id": "CVE-2020-35863",
    "published": "2020-12-31 10:15:15",
    "last_modified": "2026-06-17 03:14:29",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-444",
    "description": "An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.",
    "epss_score": "0.02974",
    "epss_percentile": "0.86895",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-11 18:17:23",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (9.8), but no sign of active exploitation."
    },
    "products": [
        {
            "vendor": "hyper",
            "product": "hyper"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://rustsec.org/advisories/RUSTSEC-2020-0008.html",
        "https://rustsec.org/advisories/RUSTSEC-2020-0008.html"
    ]
}