nixl is vulnerable to Use After Free
20
Low Risk
Affected versions of this package are vulnerable to a Use-After-Free after disconnect due to improper management of the transfer request ownership. An attacker could potentially exploit this vulnerability by triggering an error condition that causes the agent to prematurely free a request object, resulting in the client application using a dangling pointer. This use of a freed resource could result in a crash or data corruption.
You are affected if you are using a version that falls within the vulnerable range.
nixl is vulnerable to Use After Free in versions 0.1.0 - 0.6.0.
Upgrade the nixl library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant