Intel

AIKIDO-2025-10272

rustc-serialize is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

70

High Risk

This Affects:

TL;DR

The rustc-serialize package will no longer be maintained as declared by the developer. By fuzzing the package, we can identify multiple vulnerabilities. The project has been archived and cannot submit issues. The developer has recommended using the serde crate instead.

Who does this affect?

You are affected if you are using this package.

Background info

rustc-serialize is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any rustc-serialize package from your application. Please take a look at serde instead.