Kanna is vulnerable to Use-After-Free
71
High Risk
Affected versions of this package are vulnerable to memory corruption due to a use-after-free error stemming from the unsafe conversion of Swift strings to temporary C buffers during XML parsing. By passing temporary cString pointers to xmlReadDoc(), heap memory can be deallocated before finishing parsing. An attacker could exploit this issue by sending multiple large XML/HTML payloads, causing crashes, or through targeted memory grooming to leak sensitive data, like authentication tokens from freed memory.
You are affected if you are using a version that falls within the vulnerable range.
Kanna is vulnerable to Use-After-Free in versions 4.0.0 - 6.0.0.
Upgrade the Kanna library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant