—
RUSTSEC-2026-0079
`DynFuture` drop can construct a dangling reference
Details
DynFuture is unsound because its Drop implementation transmutes a trait-object reference into unrelated reference types, which constructs an invalid reference from trait object metadata.
This issue was reproduced against `dyn-future` 3.0.4 under Miri. And the crate is unmaintained.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/dyn-future
Introduced in:
0.0.0-0No fixed version published yet for dyn-future. Pin to a known-safe version or switch to an alternative.