Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhw4-xg65-fp2x

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

serde_yml crate is unsound and unmaintained

Using serde_yml::ser::Serializer.emitter can cause a segmentation fault, which is unsound.

The GitHub project for serde_yml was archived after unsoundness issues were raised.

If you rely on this crate, it is highly recommended switching to a maintained alternative.

Recommended alternatives

  • serde_norway - Maintained fork of serde_yaml, using unsafe-libyaml-norway
  • serde_yaml_ng - Maintained fork of serde_yaml, using unmaintained unsafe-libyaml

Incomplete pure Rust alternatives

These implementation do not rely on C libyaml.

Пакеты

Наименование

serde_yml

rust
Затронутые версииВерсия исправления

<= 0.0.12

Отсутствует

6.9 Medium

CVSS4

Дефекты

CWE-787

6.9 Medium

CVSS4

Дефекты

CWE-787