temporal_rs is vulnerable to Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
15
Low Risk
Affected versions of this package are vulnerable to Undefined Behavior in time duration rounding calculations due to improper use of unsafe Rust code. The vulnerability occurs when unit_length is zero, which triggers undefined behavior when passed to NonZeroU128::new_unchecked without validation. An attacker could exploit this by providing malicious input that results in a zero unit_length value, potentially causing application crashes or memory corruption depending on how the undefined behavior manifests in the execution environment.
You are affected if you are using a version that falls within the vulnerable range.
temporal_rs is vulnerable to Reliance on Undefined, Unspecified, or Implementation-Defined Behavior in versions 0.0.5 - 0.0.12.
Upgrade the temporal_rs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant