An open API service providing security vulnerability metadata for many open source software ecosystems.

MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVycnYtbTM2aC1xd2Y4

Critical EPSS: 0.00509% (0.65413 Percentile) EPSS:

Use-after-free in chttp

Affected Packages Affected Versions Fixed Versions
cargo:chttp >= 0.1.1, < 0.1.3 0.1.3
3 Dependent packages
5 Dependent repositories
92,164 Downloads total

Affected Version Ranges

All affected versions

0.1.1, 0.1.2

All unaffected versions

0.1.3, 0.1.4, 0.1.5, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.3.0, 0.3.1, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5

The From implementation for Vec was not properly implemented, returning a vector backed by freed memory. This could lead to memory corruption or be exploited to cause undefined behavior.

A fix was published in version 0.1.3.

References: