VDB
Sign up
—

RUSTSEC-2026-0130

Out-of-bounds read/write in `Index` and `IndexMut` implementations

Details

The `Index` and `IndexMut` implementations for `Caja` use unchecked pointer arithmetic without bounds validation. Creating a `Caja` with a small key and then accessing an out-of-range index causes out-of-bounds reads or writes beyond the allocated memory.

This can be triggered through safe public APIs — the `[]` indexing operator on a `Caja` with an out-of-range index — with no `unsafe` required from the caller.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/caja
Introduced in: 0.0.0-0Fixed in: 0.3.0

Upgrade caja to 0.3.0 or newer (ecosystem crates.io).

References