—
RUSTSEC-2022-0030
Stack overflow during recursive expression parsing
Details
When parsing untrusted rulex expressions, the stack may overflow, possibly enabling a Denial of Service attack. This happens when parsing an expression with several hundred levels of nesting, causing the process to abort immediately.
The flaw was corrected in commits `60aa2dc03a` by adding a check to recursion depth.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rulex
Introduced in:
0.0.0-0Fixed in: 0.4.3Upgrade rulex to 0.4.3 or newer (ecosystem crates.io).