This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-fm79-3f68-h2fc. For more information see the GitHub-hosted security advisory.
This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.
fvm(29 total, 9 outdated, 1 possibly insecure)
| Crate | Required | Latest | Status |
|---|---|---|---|
| ambassador | ^0.4.0 | 0.5.0 | out of date |
| anyhow | ^1.0.71 | 1.0.102 | up to date |
| arbitrary | ^1.3.0 | 1.4.2 | up to date |
| cid | ^0.11.1 | 0.11.1 | up to date |
| derive_more | ^1.0.0 | 2.1.1 | out of date |
| filecoin-proofs-api | ^18 | 19.1.0 | out of date |
| fvm-wasm-instrument | ^0.4.0 | 0.4.0 | up to date |
| fvm_ipld_amt | ^0.7.3 | 0.7.5 | up to date |
| fvm_ipld_blockstore | ^0.3.1 | 0.3.1 | up to date |
| fvm_ipld_encoding | ^0.5.1 | 0.5.3 | up to date |
| fvm_ipld_hamt | ^0.10.2 | 0.10.4 | up to date |
| fvm_shared | ~4.5.3 | 4.7.5 | out of date |
| lazy_static | ^1.4.0 | 1.5.0 | up to date |
| log | ^0.4.19 | 0.4.29 | up to date |
| minstant | ^0.1.3 | 0.1.7 | up to date |
| multihash-codetable | ^0.1.4 | 0.1.4 | up to date |
| multihash-derive | ^0.9.1 | 0.9.1 | up to date |
| num-traits | ^0.2.14 | 0.2.19 | up to date |
| quickcheck | ^1.0.0 | 1.1.0 | up to date |
| rand | ^0.8.5 | 0.10.0 | out of date |
| rayon | ^1 | 1.11.0 | up to date |
| replace_with | ^0.1.7 | 0.1.8 | up to date |
| serde | ^1.0.164 | 1.0.228 | up to date |
| serde_tuple | ^0.5.0 | 1.1.3 | out of date |
| static_assertions | ^1.1.0 | 1.1.0 | up to date |
| thiserror | ^1.0.40 | 2.0.18 | out of date |
| wasmtime ⚠️ | ^25.0.3 | 42.0.1 | out of date |
| wasmtime-environ | ^25.0.2 | 42.0.1 | out of date |
| yastl | ^0.1.2 | 0.1.2 | up to date |
(2 total, all up-to-date)
| Crate | Required | Latest | Status |
|---|---|---|---|
| coverage-helper | ^0.2.0 | 0.2.4 | up to date |
| pretty_assertions | ^1.3.0 | 1.4.1 | up to date |
wasmtime: Host panic with `fd_renumber` WASIp1 functionThis is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-fm79-3f68-h2fc. For more information see the GitHub-hosted security advisory.
wasmtime: Unsound API access to a WebAssembly shared linear memoryThis is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-hc7m-r6v8-hg9q For more information see the GitHub-hosted security advisory.
wasmtime: Guest-controlled resource exhaustion in WASI implementationsThis is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-852m-cvvp-9p4w For more information see the GitHub-hosted security advisory.
wasmtime: Panic adding excessive fields to a `wasi:http/types.fields` instanceThis is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-243v-98vx-264h For more information see the GitHub-hosted security advisory.