subst is vulnerable to Undefined Behavior
25
Low Risk
Affected versions of this package are vulnerable to a panic caused by an index out-of-bounds error in the parse method when the input ends with a $ character. This can lead to unexpected application crashes when processing malformed or specially crafted input.
You are affected if you are using a version which is within vulnerability ranges and using template::UriTemplateStr.
subst is vulnerable to Undefined Behavior in versions 0.3.2 - 0.3.7.
Upgrade the subst library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant