CVE-2020-15694: Nim-Lang Nim

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

In Nim 1.2.4, the standard library httpClient fails to properly validate the server response. For example, httpClient.get().contentLength() does not raise any error if a malicious server provides a negative Content-Length.

Affected products

Published 2020-08-14. Last modified 2026-06-17.