VDB
KO

RUSTSEC-2026-0218

`Enum` trait allows type confusion when manually implemented

Details

Affected versions of this crate did not require the element type of the `Array` associated type in the `Enum` trait to match the array's generic parameter `V`.

This can result in type confusion, and consequently memory corruption, when a manual `Enum` implementation declares an `Array<V>` whose elements are not actually of type `V`:

```rust struct IntentionallyWrong;

impl Enum for IntentionallyWrong { type Array<V> = [String; 4];

fn from_usize(_: usize) -> Self { IntentionallyWrong }

fn into_usize(self) -> usize { 0 } }

enum_map! { IntentionallyWrong => 42 }; ```

The flaw was corrected in commit [7a8b815432](https://codeberg.org/sugar700/enum-map/commit/7a8b8154323d426415a10accf104cd05c394cda9) by adding a `Value = V` bound to the `Array` type in the `Enum` trait.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / enum-map
Introduced in: 3.0.0-0.gat.0 Fixed in: 3.1.0

Upgrade enum-map to 3.1.0 or newer (ecosystem crates.io).

References