jiter is vulnerable to Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
44
Medium Risk
Affected versions of this package contain a soundness issue in functions that allowed skipping UTF-8 validation via an is_ascii flag. This could lead to memory safety violations if non-ASCII strings were incorrectly marked as ASCII. An attacker could exploit this vulnerability by supplying a malicious string containing non-ASCII Unicode, triggering undefined behavior that could result in panic, crashes, or memory corruption.
You are affected if you are using a version that falls within the vulnerable range.
jiter is vulnerable to Reliance on Undefined, Unspecified, or Implementation-Defined Behavior in versions 0.2.0 - 0.9.1.
Upgrade the jiter library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant