Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.
This project contains known security vulnerabilities. Find detailed information at the bottom.
pprof(17 total, 8 outdated, 1 insecure)
| Crate | Required | Latest | Status |
|---|---|---|---|
| backtrace | ^0.3 | 0.3.76 | up to date |
| cfg-if | ^1.0 | 1.0.5 | up to date |
| criterion | ^0.3 | 0.8.2 | out of date |
| findshlibs | ^0.10 | 0.10.2 | up to date |
| inferno | ^0.11 | 0.12.8 | out of date |
| libc | ^0.2.66 | 0.2.189 | up to date |
| log | ^0.4 | 0.4.34 | up to date |
| nix | ^0.24 | 0.31.3 | out of date |
| once_cell | ^1.9 | 1.21.4 | up to date |
| parking_lot | ^0.12 | 0.12.5 | up to date |
| prost | ^0.10 | 0.14.4 | out of date |
| prost-derive | ^0.10 | 0.14.4 | out of date |
| protobuf ⚠️ | ^2.0 | 3.7.2 | insecure |
| smallvec | ^1.7 | 1.16.2 | up to date |
| symbolic-demangle | ^9.0 | 13.9.0 | out of date |
| tempfile | ^3.1 | 3.27.0 | up to date |
| thiserror | ^1.0 | 2.0.21 | out of date |
(2 total, 2 outdated)
| Crate | Required | Latest | Status |
|---|---|---|---|
| criterion | ^0.3 | 0.8.2 | out of date |
| rand | ^0.8.0 | 0.10.3 | out of date |
protobuf: Crash due to uncontrolled recursion in protobuf crateAffected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.