VDB
Sign up
—

RUSTSEC-2025-0068

serde_yml crate is unsound and unmaintained

Details

Using `serde_yml::ser::Serializer.emitter` can cause a segmentation fault, which is unsound.

The GitHub project for `serde_yml` was archived after unsoundness issues were raised.

If you rely on this crate, it is highly recommended switching to a maintained alternative.

## Recommended alternatives

- [`serde_norway`](https://crates.io/crates/serde_norway) - Maintained fork of `serde_yaml`, using `unsafe-libyaml-norway` - [`serde_yaml_ng`](https://crates.io/crates/serde_yaml_ng) - Maintained fork of `serde_yaml`, using unmaintained `unsafe-libyaml`

## Incomplete pure Rust alternatives

These implementation do not rely on C `libyaml`.

- [`serde_yaml2`](https://crates.io/crates/serde_yaml2) - [`yaml-peg`](https://crates.io/crates/yaml-peg)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/serde_yml
Introduced in: 0.0.0-0

No fixed version published yet for serde_yml. Pin to a known-safe version or switch to an alternative.

References