Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. tanton_engine
  4. ›
  5. GHSA-m2xr-2vj4-wh94

GHSA-m2xr-2vj4-wh94: tanton_engine has unsound public API

May 6, 2025

The following functions in the tanton_engine crate are unsound due to lack of sufficient boundary checks in public API:

  • Stack::offset()
  • ThreadStack::get()
  • RootMoveList::insert_score_depth()
  • RootMoveList::insert_score()

The tanton_engine crate is no longer maintained, so there are no plans to fix this issue.

References

  • github.com/advisories/GHSA-m2xr-2vj4-wh94
  • rustsec.org/advisories/RUSTSEC-2025-0031.html

Code Behaviors & Features

Detect and mitigate GHSA-m2xr-2vj4-wh94 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.0.0

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Source file

cargo/tanton_engine/GHSA-m2xr-2vj4-wh94.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 13 May 2025 12:14:59 +0000.