Advisories for Cargo/Scaly package

2026

scaly: Multiple soundness issues in Rust safe APIs

Affected versions contain multiple safe APIs that can trigger undefined behavior: Array<T>::index can perform an out-of-bounds read. String::get_length can perform an out-of-bounds read. String::append_character can perform an invalid write. String::to_c_string can perform an out-of-bounds write. These issues were reproduced against scaly 0.0.37 under Miri. The crate is unmaintained.