{"id":"GHSA-gfxp-f68g-8x78","aliases":["RUSTSEC-2025-0067"],"url":"https://o3.security/vulnerability/GHSA-gfxp-f68g-8x78","summary":"LibYML: `libyml::string::yaml_string_extend` is unsound and unmaintained","details":"In version 0.0.4, `libyml::string::yaml_string_extend` was revised resulting in undefined behaviour, which is unsound.\n\nThe GitHub project for `libyml` was archived after unsoundness issues were raised.\n\nIf you rely on this crate, it is highly recommended switching to a maintained alternative.\n\n## Recommended alternatives\n\n- [`libyaml-safer`](https://crates.io/crates/libyaml-safer) \n- [`unsafe-libyaml-norway`](https://crates.io/crates/unsafe-libyaml-norway) - Maintained fork of `unsafe-libyaml`","published":"2025-09-15T13:57:29Z","modified":"2025-10-28T06:29:24.654618Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"libyml","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rustsec/advisory-db/issues/2395"},{"type":"PACKAGE","url":"https://github.com/sebastienrousseau/libyml"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0067.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:24.654618Z"}}