VDB
Sign up
HIGH7.5

GHSA-hgxq-hcrm-c5pm

opcua Vulnerable to Out-of-bounds Write

Details

The package opcua from 0.0.0 until 0.11.0 is vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, when it allows unlimited nesting levels, which could result in a stack overflow even if the message size is less than the maximum allowed.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/opcua
Introduced in: 0Fixed in: 0.11.0

Upgrade opcua to 0.11.0 or newer (ecosystem crates.io).

References