fragile is vulnerable to Use After Free
50
Medium Risk
Sticky (from the fragile package) validates access by comparing the current thread's ID against the ID recorded at creation, then reads the matching entry straight out of a global thread local registry. The registry does not track whether a thread's storage has since been torn down and reinitialized, so a handle created before teardown can still read or drop an entry that now belongs to a different, replaced registry generation, producing a stale or dangling access. A panic raised while that teardown runs aborts the whole process instead of failing safely. The fix adds a registry generation check and a teardown aware thread ID lookup so stale entries are rejected instead of accessed.
You are affected if you are using a version that falls within the vulnerable range and you apply the optional slab feature.
fragile is vulnerable to Use After Free in versions 1.2.0 - 2.1.0.
Upgrade the fragile library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.