An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
No PoCs from references.
- https://github.com/Artisan-Lab/Rust-memory-safety-bugs
- https://github.com/xxg1413/rust-security