3.3.3
7 years ago
18 days ago
Known vulnerabilities in the io.ktor:ktor-client-cio package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
io.ktor:ktor-client-cio is a framework for quickly creating web applications in Kotlin with minimal effort. Affected versions of this package are vulnerable to HTTP Request Smuggling due to a race condition between multiple coroutines using the same thread. How to fix HTTP Request Smuggling? Upgrade | [,3.1.1) |
io.ktor:ktor-client-cio is a framework for quickly creating web applications in Kotlin with minimal effort. Affected versions of this package are vulnerable to HTTP Request Smuggling. Request smuggling is possible when running behind a proxy that doesn't handle Content-Length and Transfer-Encoding properly or doesn't handle How to fix HTTP Request Smuggling? Upgrade | [,1.3.0) |