cranelift-codegen is vulnerable to Improper Handling of Exceptional Conditions
21
Low Risk
Affected versions of this package are vulnerable to improper handling of exceptional conditions in the implementation of component-model host-to-WASM trampolines. A malicious actor can craft a specially designed component and invoke it in a way that exploits the setjmp and longjmp functions in C, potentially causing the host to crash through a segmentation fault or assertion failure.
You are affected if you are using a version which is within vulnerability ranges
cranelift-codegen is vulnerable to Improper Handling of Exceptional Conditions in versions 0.88.0 - 0.124.2.
Upgrade the cranelift-codegen library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant