Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. anon-vec
  4. ›
  5. GHSA-pr59-jjr4-gcf6

GHSA-pr59-jjr4-gcf6: anon-vec lacks sufficient checks in public API

June 5, 2025

The following functions in the anon-vec crate are unsound due to insufficient checks on their arguments::

  • AnonVec::get_ref()
  • AnonVec::get_mut()
  • AnonVec::remove_get()

The crate was built as a learning project and is not being maintained.

References

  • github.com/RylanYancey/anon-vec
  • github.com/advisories/GHSA-pr59-jjr4-gcf6
  • rustsec.org/advisories/RUSTSEC-2025-0039.html

Code Behaviors & Features

Detect and mitigate GHSA-pr59-jjr4-gcf6 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.1.1

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-20: Improper Input Validation

Source file

cargo/anon-vec/GHSA-pr59-jjr4-gcf6.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:18:54 +0000.