This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate crusty-core

Dependencies

(27 total, 18 outdated, 1 insecure)

CrateRequiredLatestStatus
 tokio^1.141.53.2up to date
 strum~0.240.28.0out of date
 tracing-tools~0.5.00.6.0out of date
 flume~0.10.50.12.0out of date
 futures-lite~1.12.02.6.1out of date
 serde~1.0.1251.0.229up to date
 hyper~0.14.121.12.0out of date
 robotstxt-with-cache~0.4.00.4.0up to date
 trust-dns-resolver~0.22.00.23.2out of date
 hyper-tls~0.5.00.6.0out of date
 url~2.3.12.5.8out of date
 http~0.2.31.5.0out of date
 bytes ⚠️~1.3.01.12.1insecure
 flate2~1.0.201.1.10out of date
 select~0.6.00.6.1up to date
 ipnet~2.7.02.12.2out of date
 humansize~2.1.32.1.3up to date
 humanize-rs~0.1.50.1.5up to date
 tracing~0.1.250.1.44up to date
 thiserror~1.0.242.0.21out of date
 anyhow~1.0.401.0.104up to date
 pin-project~1.0.71.1.13out of date
 lazy_static~1.4.01.5.1out of date
 num_cpus~1.15.01.17.0out of date
 rand~0.8.00.10.3out of date
 derivative~2.2.02.2.0up to date
 core_affinity~0.7.60.8.3out of date

Dev dependencies

(4 total, 2 outdated)

CrateRequiredLatestStatus
 html5ever~0.26.00.40.1out of date
 markup5ever~0.11.00.40.0out of date
 tracing-subscriber~0.3.20.3.23up to date
 tracing~0.1.250.1.44up to date

Security Vulnerabilities

bytes: Integer overflow in `BytesMut::reserve`

RUSTSEC-2026-0007

In the unique reclaim path of BytesMut::reserve, the condition

if v_capacity >= new_cap + offset

uses an unchecked addition. When new_cap + offset overflows usize in release builds, this condition may incorrectly pass, causing self.cap to be set to a value that exceeds the actual allocated capacity. Subsequent APIs such as spare_capacity_mut() then trust this corrupted cap value and may create out-of-bounds slices, leading to UB.

This behavior is observable in release builds (integer overflow wraps), whereas debug builds panic due to overflow checks.

PoC

use bytes::*;

fn main() {
    let mut a = BytesMut::from(&b"hello world"[..]);
    let mut b = a.split_off(5);

    // Ensure b becomes the unique owner of the backing storage
    drop(a);

    // Trigger overflow in new_cap + offset inside reserve
    b.reserve(usize::MAX - 6);

    // This call relies on the corrupted cap and may cause UB & HBO
    b.put_u8(b'h');
}

Workarounds

Users of BytesMut::reserve are only affected if integer overflow checks are configured to wrap. When integer overflow is configured to panic, this issue does not apply.