An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure. Reference: https://rustsec.org/advisories/RUSTSEC-2021-0081.html
Created rust-actix-http tracking bugs for this issue: Affects: fedora-34 [bug 1993529]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-38512