Intel

AIKIDO-2025-10003

tempfile is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

40

Medium Risk

This Affects:

rusttempfile
3.0.0 - 3.14.0
Fixed in 3.15.0

TL;DR

Affected versions of this package are affected by a potential Denial of Service (DoS) vulnerability that may arise from the use of predictable randomness in the context of repeated failures when creating temporary files. Such a vulnerability could facilitate an attacker’s ability to exploit the system by leveraging the inadequacies of the randomness employed, ultimately leading to disruptions in service availability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tempfile is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 3.14.0.

How to fix this

Upgrade the tempfile library to the patch version.