jsonschema-rs is vulnerable to Use-After-Free
36
Low Risk
Affected versions of this package are vulnerable to use-after-free due to incorrect lifetime handling during asynchronous $ref resolution. When multiple $ref references point to the same external schema URL but use different fragments, internal state can be freed prematurely and later accessed again. This can result in undefined behavior, including crashes or other memory safety issues, during schema validation.
You are affected if you are using a version that falls within the vulnerable range.
jsonschema-rs is vulnerable to Use-After-Free in versions 0.29.0 - 0.37.4.
Upgrade the jsonschema-rs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant