This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate webserver

Dependencies

(50 total, 24 outdated, 2 insecure)

CrateRequiredLatestStatus
 serde^11.0.229up to date
 serde_derive^11.0.229up to date
 serde_json^11.0.151up to date
 git2^0.130.21.0out of date
 anyhow^11.0.104up to date
 libflate^12.3.2out of date
 xz2^0.10.1.7up to date
 sodiumoxide^0.20.2.7up to date
 dotenv^0.150.15.0up to date
 lazy_static^11.5.1up to date
 if_chain^11.0.3up to date
 unicode-segmentation^11.13.3up to date
 toml^0.51.1.7+spec-1.1.0out of date
 ipnetwork^0.180.21.1out of date
 r2d2^0.80.8.10up to date
 r2d2_redis^0.140.14.0up to date
 sidekiq^0.90.14.0out of date
 unicode_categories^0.10.1.1up to date
 tera^0.112.4.0out of date
 ammonia^34.2.1out of date
 html5ever^0.250.40.1out of date
 markup5ever_rcdom^0.10.39.0+unofficialout of date
 url^22.5.8up to date
 unicase^22.10.0up to date
 one-time^0.10.1.0up to date
 mime^0.30.3.17up to date
 hmac^0.110.13.0out of date
 sha-1^0.90.10.1out of date
 md-5^0.90.11.0out of date
 rand^0.80.10.3out of date
 sha2^0.90.11.0out of date
 csv^11.4.0up to date
 unic-langid^0.90.9.6up to date
 fluent-bundle^0.150.16.0out of date
 fluent-syntax^0.110.12.0out of date
 intl-memoizer^0.50.5.3up to date
 data-encoding^22.11.1up to date
 image^0.230.25.10out of date
 libwebp-sys ⚠️^0.40.14.4insecure
 regex^11.13.1up to date
 serde_regex^11.2.0up to date
 rocket^0.40.5.1out of date
 rocket_contrib^0.40.4.11up to date
 uuid^0.81.27.0out of date
 diesel ⚠️^12.3.14insecure
 chrono^0.40.4.45up to date
 comrak^0.120.56.0out of date
 multipart^0.180.18.0up to date
 parking_lot^0.110.12.5out of date
 reqwest^0.110.13.5out of date

Build dependencies

(6 total, 3 outdated)

CrateRequiredLatestStatus
 git2^0.130.21.0out of date
 serde^11.0.229up to date
 serde_derive^11.0.229up to date
 serde_json^11.0.151up to date
 toml^0.51.1.7+spec-1.1.0out of date
 tera^12.4.0out of date

Crate worker_delete_directory

No external dependencies! 🙌

Crate worker_email

Dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 serde^11.0.229up to date
 serde_derive^11.0.229up to date
 toml^0.51.1.7+spec-1.1.0out of date

Crate worker_expire_paste

Dependencies

(5 total, 2 outdated, 1 insecure)

CrateRequiredLatestStatus
 anyhow^11.0.104up to date
 chrono^0.40.4.45up to date
 dotenv^0.150.15.0up to date
 uuid^0.81.27.0out of date
 diesel ⚠️^12.3.14insecure

Security Vulnerabilities

libwebp-sys: libwebp: OOB write in BuildHuffmanTable

RUSTSEC-2023-0061

Google and Mozilla have released security advisories for RCE due to heap overflow in libwebp. Google warns the vulnerability has been exploited in the wild.

libwebp needs to be updated to 1.3.2 to include a patch for "OOB write in BuildHuffmanTable".

diesel: Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

RUSTSEC-2024-0365

The following presentation at this year's DEF CON was brought to our attention on the Diesel Gitter Channel:

SQL Injection isn't Dead: Smuggling Queries at the Protocol Level
http://web.archive.org/web/20240812130923/https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Paul%20Gerste%20-%20SQL%20Injection%20Isn't%20Dead%20Smuggling%20Queries%20at%20the%20Protocol%20Level.pdf
(Archive link for posterity.) Essentially, encoding a value larger than 4GiB can cause the length prefix in the protocol to overflow, causing the server to interpret the rest of the string as binary protocol commands or other data.

It appears Diesel does perform truncating casts in a way that could be problematic, for example: https://github.com/diesel-rs/diesel/blob/ae82c4a5a133db65612b7436356f549bfecda1c7/diesel/src/pg/connection/stmt/mod.rs#L36

This code has existed essentially since the beginning, so it is reasonable to assume that all published versions <= 2.2.2 are affected.

Mitigation

The prefered migration to the outlined problem is to update to a Diesel version newer than 2.2.2, which includes fixes for the problem.

As always, you should make sure your application is validating untrustworthy user input. Reject any input over 4 GiB, or any input that could encode to a string longer than 4 GiB. Dynamically built queries are also potentially problematic if it pushes the message size over this 4 GiB bound.

For web application backends, consider adding some middleware that limits the size of request bodies by default.

Resolution

Diesel now uses #[deny] directives for the following Clippy lints:

to prevent casts that will lead to precision loss or other trunctations. Additionally we performed an audit of the relevant code.

A fix is included in the 2.2.3 release.

diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`

RUSTSEC-2026-0136

Diesel allows users to configure various options for PostgreSQL's COPY FROM and COPY TO statements. These configurations are partially provided as strings or characters.

Diesel did not check if any these user-provided options contain a quote character ', which can lead to the injection of additional options in the current COPY FROM/COPY TO statement.

This vulnerability affects any user of COPY FROM/COPY TO that passes user-provided input to any of the affected functions. It can result in modifications of options in the current statement, but it is not possible inject additional statements.

Mitigation

The preferred mitigation to the outlined problem is to update to Diesel version 2.3.8 or newer, which includes fixes for the problem.

Resolution

Diesel now correctly escapes any quotes contained in the provided arguments.

diesel: Possible unaligned data access for implementations of `SqliteAggregate`

RUSTSEC-2026-0137

Diesel allows to register custom aggregate SQL functions for SQLite via the SqliteAggregate interface.

To store an instance of the custom aggregate processor Diesel relied on the sqlite3_aggregate_context function provided by sqlite. This function doesn't provide any guarantees about alignment of the returned allocation, which in turn can lead to problems if the type implementing requires a special alignment, e.g. via a custom #[align(x)] attribute on the type implementing this trait. This affects any user of SqliteAggregate that registers the custom aggregate function with an SQLite connection, while using a non-standard alignment on the type implementing this trait.

Mitigation

The preferred mitigation to the outlined problem is to update to a Diesel version 2.3.8 or newer, which includes fixes for the problem.

Resolution

Diesel now allocates the corresponding memory on Rust side to get a correctly aligned allocation.