RUSTSEC-2025-0143
Unsound APIs of public `constant::Reader` and `StructSchema`
Details
The safe API functions `constant::Reader::get` and `StructSchema::new` rely on `PointerReader::get_root_unchecked`, which can cause undefined behavior (UB) by constructing arbitrary words or schemas.
## `Reader::get`
```rust pub fn get(&self) -> Result<<T as Owned>::Reader<'static>> { // ... // UNSAFE: access `words` without validation } ```
## `StructSchema::new`
```rust pub fn new(builder: RawBrandedStructSchema) -> StructSchema { // ... // UNSAFE: access encoded nodes without validation } ```
This vulnerability allows safe Rust code to trigger UB, which violates Rust's safety guarantees.
The issue is resolved in version `0.24.0` by making constructor functions unsafe and mark the fields of struct as visible only in the crate.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.24.0Upgrade capnp to 0.24.0 or newer (ecosystem crates.io).