RUSTSEC-2026-0242
Safe ErrorRegistry APIs can cause undefined behavior
Details
All published versions of `dcrypt-api` before 2.0.0 exposed safe `ErrorRegistry` operations that could trigger undefined behavior when the default `std` feature was enabled.
Stored `Box<E>` values were erased to raw pointers and later deallocated as `Box<()>`. The `get_error<E>` operation also performed an unchecked cast to a caller-selected type. Finally, concurrent replacement or clearing could free a value while another thread cloned it. Ordinary safe Rust could therefore cause mismatched deallocation, type confusion, and use-after-free. Crates that re-exported this API are affected transitively.
Version 2.0.0 replaces the raw pointers with owned `Box<dyn Any + Send>` values behind a mutex, performs checked downcasts, and uses a mutation generation so concurrent stores and clears win safely. There is no reliable workaround while calling the affected registry API. Upgrade to 2.0.0 or later and avoid process-global error state where possible.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0 Fixed in: 2.0.0 Upgrade dcrypt-api to 2.0.0 or newer (ecosystem crates.io).
References
- https://crates.io/crates/dcrypt-api [PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2026-0242.html [ADVISORY]
- https://github.com/ioi-foundation/dcrypt/security/advisories/GHSA-7hc7-h3f2-r4j6 [ADVISORY]
- https://github.com/ioi-foundation/dcrypt/commit/c99cc86f0ee353010cd202cbcd2c310371b0bbb8 [WEB]
- https://github.com/ioi-foundation/dcrypt/releases/tag/v2.0.0 [WEB]