VDB
Sign up
HIGH7.5

GHSA-vjrq-cg9x-rfjp

Improper Input Validation in cookie

Details

Affected versions of this crate use the time crate and the method Duration::seconds to parse the Max-Age duration cookie setting. This method will panic if the value is greater than 2^64/1000 and less than or equal to 2^64, which can result in denial of service for a client or server.

This flaw was corrected by explicitly checking for the Max-Age being in this integer range and clamping the value to the maximum duration value.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/cookie
Introduced in: 0Fixed in: 0.7.6

Upgrade cookie to 0.7.6 or newer (ecosystem crates.io).

References