{"id":"GHSA-466c-pfvv-v83g","aliases":["RUSTSEC-2025-0072"],"url":"https://o3.security/vulnerability/GHSA-466c-pfvv-v83g","summary":"wrflib has a soundness issue and is unmaintained","details":"All functions under `wrflib::byte_extract` are simply wrapper of unsafe pointer offset and lacks sufficient checks to it pointer and offset parameter.\n\n`wrflib` is unmaintained.","published":"2025-10-03T19:25:09Z","modified":"2025-10-28T06:29:22.855364Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"wrflib","fixedVersion":null}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/cruise-automation/webviz-rust-framework"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0072.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:22.855364Z"}}