foyer-storage is vulnerable to Use After Free
50
Medium Risk
Affected versions of this package contain a vulnerability known as a heap-use-after-free issue in the PsyncIoEngine. It arises from improper buffer handling during the cancellation of tasks in I/O operations, which can lead to memory corruption. An attacker could exploit this vulnerability by strategically canceling tasks to trigger the use-after-free condition, potentially resulting in arbitrary code execution or a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
foyer-storage is vulnerable to Use After Free in versions 0.19.0 - 0.19.2.
Upgrade the foyer-storage library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant