tungstenite is vulnerable to Undefined Behavior
18
Low Risk
Affected versions of this package are vulnerable to undefined behavior when handling unreliable Read stream implementations. The issue arises from improper memory handling during stream processing. The updated version resolves this by retaining the set-len refactor while employing a safe resize function to prevent such issues.
You are affected if you are using a version that falls within the vulnerable range.
tungstenite is vulnerable to Undefined Behavior in versions 0.26.0 - 0.26.0.
Upgrade the tungstenite library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant