GHSA-mcrf-7hf9-f6q5: Unchecked vector pre-allocation
(updated )
Affected versions of this crate pre-allocate memory on deserializing raw buffers without checking whether there is sufficient data available. This allows an attacker to do denial-of-service attacks by sending small msgpack messages that allocate gigabytes of memory.
References
Detect and mitigate GHSA-mcrf-7hf9-f6q5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →