VDB
Sign up
—

RUSTSEC-2024-0379

Multiple soundness issues

Details

`fast-float` contains multiple soundness issues:

1. [Undefined behavior when checking input length](https://github.com/aldanor/fast-float-rust/issues/28), which has been merged but no package [pubished](https://github.com/aldanor/fast-float-rust/issues/35). 1. [Many functions marked as safe with non-local safety guarantees](https://github.com/aldanor/fast-float-rust/issues/37)

The library is also unmaintained.

## Alternatives

For quickly parsing floating-point numbers third-party crates are generally no longer needed. A fast float parsing algorithm by the author of `lexical` has been [merged](https://github.com/rust-lang/rust/pull/86761) into libcore. When requiring direct parsing from bytes and/or partial parsers, the [`fast-float2`](https://crates.io/crates/fast-float2) fork of `fast-float` containing these security patches and reduces overall usage of unsafe.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/fast-float
Introduced in: 0.0.0-0

No fixed version published yet for fast-float. Pin to a known-safe version or switch to an alternative.

References