tungstenite is vulnerable to Undefined Behavior
18
Low Risk
Affected versions of this package are vulnerable to undefined behavior when handling unreliable Read stream implementations. The issue arises from improper memory handling during stream processing. The updated version resolves this by retaining the set-len refactor while employing a safe resize function to prevent such issues.
You are affected if you are using a version that falls within the vulnerable range.
tungstenite is vulnerable to Undefined Behavior in versions 0.26.0 - 0.26.0.
Upgrade the tungstenite library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant