Intel

AIKIDO-2025-10762

stringzilla is vulnerable to Undefined Behavior

Undefined Behavior Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 31, 2025

35

Low Risk

This Affects:

ruststringzilla
3.5.0 - 4.2.2
Fixed in 4.2.3
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to undefined behavior due to missing bounds checks in the safe Rust interface. This flaw allows out-of-bounds memory access, potentially leading to memory corruption, crashes, or other unpredictable behavior.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and using template::UriTemplateStr.

Background info

stringzilla is vulnerable to Undefined Behavior in versions 3.5.0 - 4.2.2.

How to fix this

Upgrade the stringzilla library to the patch version.