This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate token-factory-api

No external dependencies! 🙌

Crate ucs03-zkgm

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 cw-multi-test=2.43.0.1out of date

Crate ucs06-funded-dispatch

No external dependencies! 🙌

Crate multicall

No external dependencies! 🙌

Crate lst

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 hex-literal^1.01.0.0up to date

Crate lst-staker

No external dependencies! 🙌

Crate ibc-union

No external dependencies! 🙌

Crate ibc-union-msg

No external dependencies! 🙌

Crate ibc-union-light-client

No external dependencies! 🙌

Crate devnet-compose

Dependencies

(2 total, 2 outdated)

CrateRequiredLatestStatus
 cliclack^0.2.50.3.6out of date
 console^0.15.110.16.1out of date

Crate ensure-blocks

No external dependencies! 🙌

Crate protos

No external dependencies! 🙌

Crate beacon-api

No external dependencies! 🙌

Crate cometbft-rpc

Dev dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 hex-literal^0.4.11.0.0out of date
 serde_json^1.0.1401.0.145up to date
 serde_path_to_error^0.1.170.1.20up to date

Crate cosmos-client

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 num-rational^0.4.20.4.2up to date
 num-traits^0.2.190.2.19up to date

Crate cometbft-types

No external dependencies! 🙌

Crate concurrent-keyring

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tracing-subscriber^0.3.190.3.20up to date

Crate gnark-key-parser

Dependencies

(3 total, 2 outdated)

CrateRequiredLatestStatus
 ark-bls12-381^0.40.5.0out of date
 ark-serialize^0.4.20.5.0out of date
 substrate-bn^0.60.6.0up to date

Dev dependencies

(2 total, 2 outdated)

CrateRequiredLatestStatus
 ark-bn254^0.40.5.0out of date
 ark-ff^0.4.20.5.0out of date

Crate gnark-mimc

Dependencies

(3 total, 3 outdated)

CrateRequiredLatestStatus
 ark-bls12-377^0.40.5.0out of date
 ark-bn254^0.40.5.0out of date
 ark-ff^0.40.5.0out of date

Crate ics23

No external dependencies! 🙌

Crate linea-verifier

No external dependencies! 🙌

Crate linea-zktrie

No external dependencies! 🙌

Crate macros

No external dependencies! 🙌

Crate pg-queue

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 futures-util^0.3.310.3.31up to date

Crate subset-of-derive

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 trybuild^1.0.1051.0.112up to date

Crate scroll-api

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 serde_json^1.0.1401.0.145up to date

Crate scroll-codec

No external dependencies! 🙌

Crate scroll-rpc

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 serde_json^1.0.1401.0.145up to date
 tracing-subscriber^0.3.190.3.20up to date

Crate arbitrum-types

No external dependencies! 🙌

Crate arbitrum-client

No external dependencies! 🙌

Crate bob-types

No external dependencies! 🙌

Crate base-client

No external dependencies! 🙌

Crate bob-client

No external dependencies! 🙌

Crate serde-utils

No external dependencies! 🙌

Crate ssz

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 derivative^2.2.02.2.0up to date
 smallvec^1.15.01.15.1up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 serde_yaml^0.9.340.9.34+deprecatedup to date
 snap^1.1.11.1.1up to date

Crate ssz-tests-generator

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 serde_yaml^0.9.340.9.34+deprecatedup to date
 snap^1.1.11.1.1up to date

Crate ssz-derive

No external dependencies! 🙌

Crate unionlabs

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 serde_bytes^0.11.170.11.19up to date

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 rand^0.8.50.9.2out of date

Crate unionlabs-primitives

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 serde_bytes^0.11.170.11.19up to date
 uint^0.9.50.10.0out of date

Crate unionlabs-encoding

No external dependencies! 🙌

Crate galois-rpc

No external dependencies! 🙌

Crate cosmos-sdk-event

No external dependencies! 🙌

Crate frissitheto

No external dependencies! 🙌

Crate parlia-types

No external dependencies! 🙌

Crate ibc-solidity

No external dependencies! 🙌

Crate base-verifier

No external dependencies! 🙌

Crate bob-verifier

No external dependencies! 🙌

Crate arbitrum-verifier

No external dependencies! 🙌

Crate cometbls-groth16-verifier

Dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 ark-ff^0.4.20.5.0out of date
 byteorder^1.51.5.0up to date
 substrate-bn^0.60.6.0up to date

Build dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 substrate-bn^0.60.6.0up to date

Crate ethereum-sync-protocol

No external dependencies! 🙌

Crate ethereum-sync-protocol-types

No external dependencies! 🙌

Crate evm-storage-verifier

Dependencies

(4 total, 2 outdated)

CrateRequiredLatestStatus
 hash-db^0.16.00.16.0up to date
 hash256-std-hasher^0.15.20.15.2up to date
 memory-db^0.32.00.34.0out of date
 trie-db^0.280.30.0out of date

Crate parlia-verifier

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 blst^0.3.140.3.16up to date

Crate tendermint-verifier

No external dependencies! 🙌

Crate base-light-client-types

No external dependencies! 🙌

Crate bob-light-client-types

No external dependencies! 🙌

Crate arbitrum-light-client-types

No external dependencies! 🙌

Crate berachain-light-client-types

No external dependencies! 🙌

Crate cometbls-light-client-types

No external dependencies! 🙌

Crate tendermint-light-client-types

No external dependencies! 🙌

Crate ethereum-light-client-types

No external dependencies! 🙌

Crate ethermint-light-client-types

No external dependencies! 🙌

Crate movement-light-client-types

No external dependencies! 🙌

Crate parlia-light-client-types

No external dependencies! 🙌

Crate trusted-mpt-light-client-types

No external dependencies! 🙌

Crate attested-light-client-types

No external dependencies! 🙌

Crate linea-light-client-types

No external dependencies! 🙌

Crate scroll-light-client-types

No external dependencies! 🙌

Crate state-lens-ics23-mpt-light-client-types

No external dependencies! 🙌

Crate state-lens-ics23-ics23-light-client-types

No external dependencies! 🙌

Crate state-lens-ics23-smt-light-client-types

No external dependencies! 🙌

Crate sui-light-client-types

Dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 blake2^0.10.60.10.6up to date
 roaring^0.10.120.11.2out of date
 serde_repr^0.1.200.1.20up to date

Crate cosmwasm-deployer

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 num-rational^0.4.20.4.2up to date
 rand_chacha^0.3.10.9.0out of date

Crate arbitrum-light-client

No external dependencies! 🙌

Crate base-light-client

No external dependencies! 🙌

Crate berachain-light-client

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 lazy_static^1.5.01.5.0up to date

Crate bob-light-client

No external dependencies! 🙌

Crate cometbls-light-client

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 lazy_static^1.5.01.5.0up to date

Crate ethereum-light-client

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 ark-bls12-381^0.5.00.5.0up to date
 ark-ec^0.5.00.5.0up to date
 ark-serialize^0.5.00.5.0up to date

Crate ethermint-light-client

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 lazy_static^1.5.01.5.0up to date

Crate tendermint-light-client

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 lazy_static^1.5.01.5.0up to date

Crate parlia-light-client

No external dependencies! 🙌

Crate trusted-mpt-light-client

No external dependencies! 🙌

Crate attested-light-client

No external dependencies! 🙌

Crate state-lens-ics23-mpt-light-client

No external dependencies! 🙌

Crate state-lens-ics23-ics23-light-client

No external dependencies! 🙌

Crate sui-light-client

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 blake2^0.10.60.10.6up to date
 serde_repr^0.1.200.1.20up to date

Crate devnet-utils

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 bip39^2.1.02.2.0up to date
 ed25519-compact^2.1.12.1.1up to date
 tiny-hderive^0.3.00.3.0up to date

Crate build-evm-deployer-tx

No external dependencies! 🙌

Crate parse-wasm-client-type

No external dependencies! 🙌

Crate tidy

Dependencies

(3 total, 2 outdated)

CrateRequiredLatestStatus
 cargo-util-schemas^0.1.00.10.0out of date
 cargo_metadata^0.18.10.23.0out of date
 regex^1.11.31.12.2up to date

Crate rustfmt-sort

No external dependencies! 🙌

Crate move-bindgen-derive

No external dependencies! 🙌

Crate unionvisor

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 fs_extra^1.3.01.3.0up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.20.03.23.0up to date
 tracing-test^0.2.50.2.5up to date

Crate voyager

Dependencies

(5 total, 2 outdated)

CrateRequiredLatestStatus
 pin-utils^0.1.00.1.0up to date
 prometheus^0.13.40.14.0out of date
 serde_jsonc^1.0.1081.0.108up to date
 tikv-jemallocator^0.50.6.1out of date
 tracing-futures^0.2.50.2.5up to date

Crate voyager-message

No external dependencies! 🙌

Crate voyager-vm

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 enumorph^0.1.20.1.2up to date

Crate voyager-rpc

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 indexmap^2.9.02.12.0up to date

Crate voyager-core

Dependencies

(6 total, all up-to-date)

CrateRequiredLatestStatus
 derive_builder^0.20.20.20.2up to date
 indexmap^2.9.02.12.0up to date
 jaq-core^2.2.02.2.1up to date
 jaq-json^1.1.21.1.3up to date
 jaq-std^2.1.12.1.2up to date
 pin-utils^0.1.00.1.0up to date

Crate voyager-primitives

No external dependencies! 🙌

Crate voyager-state-module-cosmos-sdk

No external dependencies! 🙌

Crate voyager-state-module-cosmos-sdk-union

No external dependencies! 🙌

Crate voyager-state-module-ethereum

No external dependencies! 🙌

Crate voyager-state-module-sui

No external dependencies! 🙌

Crate voyager-proof-module-cosmos-sdk

No external dependencies! 🙌

Crate voyager-proof-module-cosmos-sdk-union

No external dependencies! 🙌

Crate voyager-proof-module-ethermint

No external dependencies! 🙌

Crate voyager-proof-module-ethereum

No external dependencies! 🙌

Crate voyager-proof-module-sui

No external dependencies! 🙌

Crate voyager-client-module-base

No external dependencies! 🙌

Crate voyager-client-module-bob

No external dependencies! 🙌

Crate voyager-client-module-arbitrum

No external dependencies! 🙌

Crate voyager-client-module-cometbls

No external dependencies! 🙌

Crate voyager-client-module-ethereum

No external dependencies! 🙌

Crate voyager-client-module-parlia

No external dependencies! 🙌

Crate voyager-client-module-tendermint

No external dependencies! 🙌

Crate voyager-client-module-ethermint

No external dependencies! 🙌

Crate voyager-client-module-state-lens-ics23-mpt

No external dependencies! 🙌

Crate voyager-client-module-state-lens-ics23-ics23

No external dependencies! 🙌

Crate voyager-client-module-state-lens-ics23-smt

No external dependencies! 🙌

Crate voyager-client-module-sui

No external dependencies! 🙌

Crate voyager-client-module-trusted-mpt

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-base

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-bob

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-arbitrum

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-cometbls

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-ethereum

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-parlia

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-tendermint

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-ethermint

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-trusted-mpt

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-state-lens-ics23-mpt

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-state-lens-ics23-smt

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-state-lens-ics23-ics23

No external dependencies! 🙌

Crate voyager-client-bootstrap-module-sui

No external dependencies! 🙌

Crate voyager-finality-module-base

No external dependencies! 🙌

Crate voyager-finality-module-bob

No external dependencies! 🙌

Crate voyager-finality-module-arbitrum

No external dependencies! 🙌

Crate voyager-finality-module-berachain

No external dependencies! 🙌

Crate voyager-finality-module-cometbls

No external dependencies! 🙌

Crate voyager-finality-module-ethereum

No external dependencies! 🙌

Crate voyager-finality-module-parlia

No external dependencies! 🙌

Crate voyager-finality-module-tendermint

No external dependencies! 🙌

Crate voyager-finality-module-trusted-evm

No external dependencies! 🙌

Crate voyager-finality-module-sui

No external dependencies! 🙌

Crate voyager-client-update-plugin-base

No external dependencies! 🙌

Crate voyager-client-update-plugin-bob

No external dependencies! 🙌

Crate voyager-client-update-plugin-arbitrum

No external dependencies! 🙌

Crate voyager-client-update-plugin-berachain

No external dependencies! 🙌

Crate voyager-client-update-plugin-cometbls

No external dependencies! 🙌

Crate voyager-client-update-plugin-ethereum

No external dependencies! 🙌

Crate voyager-client-update-plugin-parlia

No external dependencies! 🙌

Crate voyager-client-update-plugin-tendermint

No external dependencies! 🙌

Crate voyager-client-update-plugin-ethermint

No external dependencies! 🙌

Crate voyager-client-update-plugin-state-lens

No external dependencies! 🙌

Crate voyager-client-update-plugin-sui

No external dependencies! 🙌

Crate voyager-client-update-plugin-trusted-mpt

No external dependencies! 🙌

Crate voyager-periodic-client-update-plugin

No external dependencies! 🙌

Crate voyager-event-source-plugin-cosmos-sdk

No external dependencies! 🙌

Crate voyager-event-source-plugin-ethereum

No external dependencies! 🙌

Crate voyager-event-source-plugin-sui

No external dependencies! 🙌

Crate voyager-transaction-plugin-cosmos-sdk

No external dependencies! 🙌

Crate voyager-transaction-plugin-ethereum

No external dependencies! 🙌

Crate voyager-transaction-plugin-sui

No external dependencies! 🙌

Crate voyager-plugin-packet-filter

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 regex^1.11.11.12.2up to date

Crate voyager-plugin-packet-index

No external dependencies! 🙌

Crate voyager-plugin-packet-batch

No external dependencies! 🙌

Crate voyager-plugin-transaction-batch

No external dependencies! 🙌

Crate voyager-plugin-packet-timeout

No external dependencies! 🙌

Crate voyager-plugin-zkgm-filter

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 crc^3.3.03.3.0up to date

Crate voyager-sui-ibc-app-plugin-zkgm

No external dependencies! 🙌

Crate voyager-plugin-sui-packet-timeout

No external dependencies! 🙌

Crate drip

Dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 async-graphql^7.0.177.0.17up to date
 async-graphql-axum^7.0.177.0.17up to date
 async-sqlite^0.2.20.5.3out of date

Crate reconnecting-jsonrpc-ws-client

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 arc-swap^1.7.11.7.1up to date

Crate subset-of

No external dependencies! 🙌

Crate beacon-api-types

No external dependencies! 🙌

Crate mpc-shared

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 postgrest^1.61.6.0up to date

Crate mpc-client

Dependencies

(10 total, 5 outdated)

CrateRequiredLatestStatus
 async-sqlite^0.2.20.5.3out of date
 crossterm^0.27.00.29.0out of date
 futures-util^0.30.3.31up to date
 http-body-util^0.10.1.3up to date
 httpdate^1.01.0.3up to date
 hyper^11.7.0up to date
 hyper-util^0.10.1.17up to date
 pgp^0.130.17.0out of date
 ratatui^0.27.00.29.0out of date
 throbber-widgets-tui^0.60.9.0out of date

Crate mpc-coordinator

Dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 pgp^0.130.17.0out of date

Crate ibc-union-spec

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 num-traits^0.2.190.2.19up to date

Crate ibc-classic-spec

No external dependencies! 🙌

Crate state-lens-light-client-types

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tuple_join^0.1.00.1.0up to date

Crate create3

No external dependencies! 🙌

Crate linea-types

No external dependencies! 🙌

Crate osmosis-tokenfactory-token-minter

No external dependencies! 🙌

Crate cw20-token-minter

No external dependencies! 🙌

Crate cw-account

No external dependencies! 🙌

Crate access-manager

No external dependencies! 🙌

Crate access-managed

No external dependencies! 🙌

Crate cw-escrow-vault

No external dependencies! 🙌

Crate cw-unionversal-token

No external dependencies! 🙌

Crate ucs03-zkgm-token-minter-api

No external dependencies! 🙌

Crate osmosis-tokenfactory-token-owner

No external dependencies! 🙌

Crate cw20-base

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 cw2^2.0.03.0.0out of date
 semver^11.0.27up to date

Dev dependencies

(1 total, 1 outdated)

CrateRequiredLatestStatus
 cw-multi-test=2.4.03.0.1out of date

Crate cw20-wrapped-tokenfactory

No external dependencies! 🙌

Crate on-zkgm-call-proxy

No external dependencies! 🙌

Crate scroll-types

No external dependencies! 🙌

Crate fork-schedules

No external dependencies! 🙌

Crate depolama

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 num-traits^0.2.190.2.19up to date

Crate embed-commit

Dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 bytemuck^1.231.24.0up to date
 const-hex^1.14.11.17.0up to date

Crate embed-commit-verifier

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 bytemuck^1.23.01.24.0up to date
 elf^0.7.40.8.0out of date

Crate ucs04

Build dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 heck^0.5.00.5.0up to date

Crate deployments

No external dependencies! 🙌

Crate consensus-primitives

No external dependencies! 🙌

Crate solidity-slot

No external dependencies! 🙌

Crate u

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 bech32^0.11.00.11.0up to date
 keccak-asm^0.1.40.1.4up to date
 num_cpus^1.161.17.0up to date

Crate chain-kitchen

No external dependencies! 🙌

Crate json-schema-to-nixos-module-options

No external dependencies! 🙌

Crate voyager-types

No external dependencies! 🙌

Crate voyager-client

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 indexmap^2.9.02.12.0up to date

Crate voyager-plugin

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 indexmap^2.9.02.12.0up to date

Crate voyager-sdk

No external dependencies! 🙌

Crate voyager-plugin-protocol

No external dependencies! 🙌

Crate wasm-client-type

Dependencies

(2 total, 1 outdated)

CrateRequiredLatestStatus
 paste^1.01.0.15up to date
 wasmparser^0.1130.240.0out of date

Crate sui-verifier

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 blake2^0.10.60.10.6up to date

Crate ucs03-zkgm-packet

No external dependencies! 🙌

Crate update-deployments

No external dependencies! 🙌

Crate union-test

Dependencies

(1 total, 1 possibly insecure)

CrateRequiredLatestStatus
 regex ⚠️^11.12.2maybe insecure

Dev dependencies

(4 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 once_cell^1.171.21.3up to date
 rand^0.60.9.2out of date
 tokio ⚠️^11.48.0maybe insecure
 tracing-subscriber^0.30.3.20up to date

Crate cw20-ctx

No external dependencies! 🙌

Crate ucs03-zkgmable

No external dependencies! 🙌

Crate ucs03-solvable

No external dependencies! 🙌

Crate access-manager-types

No external dependencies! 🙌

Crate access-manager-tests

Dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 bip39^2.2.02.2.0up to date
 k256^0.13.40.13.4up to date
 tiny-hderive^0.3.00.3.0up to date

Crate access-managed-example

No external dependencies! 🙌

Crate aptos-types

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 serde_bytes^0.11.190.11.19up to date

Crate cosmos-signer

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 k256^0.13.40.13.4up to date

Crate upgradable

No external dependencies! 🙌

Security Vulnerabilities

regex: Regexes with large repetitions on empty sub-expressions take a very long time to parse

RUSTSEC-2022-0013

The Rust Security Response WG was notified that the regex crate did not properly limit the complexity of the regular expressions (regex) it parses. An attacker could use this security issue to perform a denial of service, by sending a specially crafted regex to a service accepting untrusted regexes. No known vulnerability is present when parsing untrusted input with trusted regexes.

This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the regex crate is used to parse untrusted regexes. Other uses of the regex crate are not affected by this vulnerability.

Overview

The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API.

Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes.

Affected versions

All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5.

Mitigations

We recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the regex crate.

Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes.

Acknowledgements

We want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix.

We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory.

tokio: reject_remote_clients Configuration corruption

RUSTSEC-2023-0001

On Windows, configuring a named pipe server with pipe_mode will force ServerOptions::reject_remote_clients as false.

This drops any intended explicit configuration for the reject_remote_clients that may have been set as true previously.

The default setting of reject_remote_clients is normally true meaning the default is also overridden as false.

Workarounds

Ensure that pipe_mode is set first after initializing a ServerOptions. For example:

let mut opts = ServerOptions::new();
opts.pipe_mode(PipeMode::Message);
opts.reject_remote_clients(true);