VDB
KO

RUSTSEC-2026-0242

Safe ErrorRegistry APIs can cause undefined behavior

Details

All published versions of `dcrypt-api` before 2.0.0 exposed safe `ErrorRegistry` operations that could trigger undefined behavior when the default `std` feature was enabled.

Stored `Box<E>` values were erased to raw pointers and later deallocated as `Box<()>`. The `get_error<E>` operation also performed an unchecked cast to a caller-selected type. Finally, concurrent replacement or clearing could free a value while another thread cloned it. Ordinary safe Rust could therefore cause mismatched deallocation, type confusion, and use-after-free. Crates that re-exported this API are affected transitively.

Version 2.0.0 replaces the raw pointers with owned `Box<dyn Any + Send>` values behind a mutex, performs checked downcasts, and uses a mutation generation so concurrent stores and clears win safely. There is no reliable workaround while calling the affected registry API. Upgrade to 2.0.0 or later and avoid process-global error state where possible.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / dcrypt-api
Introduced in: 0.0.0-0 Fixed in: 2.0.0

Upgrade dcrypt-api to 2.0.0 or newer (ecosystem crates.io).

References