github.com/bytedance/sonic is vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
88
High Risk
Prior to version 1.15.1, the decoder could corrupt memory when decoding into a prefilled interface value. This vulnerability could lead to memory corruption and undefined behavior if attackers supplied specially crafted input.
You are affected if you are using a version that falls within the vulnerable range.
github.com/bytedance/sonic is vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer in versions 0.0.1 - 1.15.0.
Upgrade the github.com/bytedance/sonic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant