Intel

AIKIDO-2025-10290

tanton_engine is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party ComponentsGHSA-m2xr-2vj4-wh94 Published May 7, 2025

30

Low Risk

This Affects:

Rusttanton_engine
0.0.0 - *
Are you affected? Scan for Free

TL;DR

Certain functions in the tanton_engine crate are unsound due to lack of sufficient boundary checks in public API. The tanton_engine crate is no longer maintained, so there are no plans to fix this issue.

Who does this affect?

You are affected if you are using this package.

Background info

tanton_engine is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any tanton_engine package from your application.