Intel

AIKIDO-2026-688677

gumdrop is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 6 days ago

50

Medium Risk

This Affects:

rustgumdrop
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The gumdrop crate is no longer maintained. Please migrate to an alternative crate.

Who does this affect?

You are affected if you are using this package.

Background info

gumdrop is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any gumdrop package from your application. Please take a look at clap or bpaf as an alternative.