---
id: RUSTSEC-2026-0181
aliases:
  - GHSA-fx4f-mhw4-qm7j
title: >-
  DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously
  crafted chunk lengths
summary: >-
  DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously
  crafted chunk lengths
severity: none
vendor: vibeio-http
product: vibeio-http
ecosystem: rust
affected:
  - 'vibeio-http >= 0.0.0-0, < 0.3.2'
patched:
  - vibeio-http 0.3.2
published: '2026-06-06'
updated: '2026-08-25'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0181'
references:
  - url: 'https://crates.io/crates/vibeio-http'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0181.html'
  - url: >-
      https://github.com/ferronweb/vibeio-http/blob/main/CHANGELOG.md#vibeio-http-032
tags:
  - osv
  - rust
ingestedAt: '2026-08-25T19:26:23.673Z'
---

## Overview

When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between `usize::MAX - 1` and `usize::MAX` inclusive) and send it, causing the server to crash (integer overflow panic in debug builds, split_to out of bounds panic in release builds).

This was fixed in `vibeio-http` 0.3.2 by erroring on the chunk length if it exceeds `usize::MAX - 2` (using `checked_add()` instead of `+` operator), preventing integer overflow.

## Affected packages

- `vibeio-http >= 0.0.0-0, < 0.3.2`

## Remediation

Upgrade to a patched release:

- `vibeio-http 0.3.2`
