VDB
Sign up
CRITICAL9.8

GHSA-5rrv-m36h-qwf8

Use-after-free in chttp

Details

The From implementation for Vec was not properly implemented, returning a vector backed by freed memory. This could lead to memory corruption or be exploited to cause undefined behavior.

A fix was published in version 0.1.3.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/chttp
Introduced in: 0.1.1Fixed in: 0.1.3

Upgrade chttp to 0.1.3 or newer (ecosystem crates.io).

References