Actix
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Actix product.
RSS Feeds for Actix security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Actix products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Actix Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Actix. Actix did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 4 | 7.50 |
It may take a day or so for new Actix vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Actix Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2018-25026 | Dec 27, 2021 |
An issue was discovered in the actix-web crate before 0.7.15 for RustAn issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between threads safely, leading to memory corruption. |
|
| CVE-2018-25025 | Dec 27, 2021 |
An issue was discovered in the actix-web crate before 0.7.15 for RustAn issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption. |
|
| CVE-2018-25024 | Dec 27, 2021 |
An issue was discovered in the actix-web crate before 0.7.15 for RustAn issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leading to memory corruption. |
|
| CVE-2021-38512 | Aug 10, 2021 |
An issue was discovered in the actix-http crate before 3.0.0-beta.9 for RustAn issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure. |
|