This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate libwebp

Dependencies

(1 total, 1 possibly insecure)

CrateRequiredLatestStatus
 libwebp-sys2 ⚠️^0.1.00.1.9maybe insecure

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 rand^0.6.50.8.5out of date

Security Vulnerabilities

libwebp-sys2: libwebp: OOB write in BuildHuffmanTable

RUSTSEC-2023-0060

Google and Mozilla have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.

libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".