CRITICAL9.8
GHSA-5rrv-m36h-qwf8
Use-after-free in chttp
Details
The From implementation for Vec was not properly implemented, returning a vector backed by freed memory. This could lead to memory corruption or be exploited to cause undefined behavior.
A fix was published in version 0.1.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/chttp
Introduced in:
0.1.1Fixed in: 0.1.3Upgrade chttp to 0.1.3 or newer (ecosystem crates.io).