{"id":"GHSA-pr59-jjr4-gcf6","aliases":["RUSTSEC-2025-0039"],"url":"https://o3.security/vulnerability/GHSA-pr59-jjr4-gcf6","summary":"anon-vec lacks sufficient checks in public API","details":"The following functions in the anon-vec crate are unsound due to insufficient checks on their arguments::\n\n- `AnonVec::get_ref()`\n- `AnonVec::get_mut()`\n- `AnonVec::remove_get()`\n\nThe crate was built as a learning project and is not being maintained.","published":"2025-06-05T00:39:55Z","modified":"2025-10-28T06:29:25.817320Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"anon-vec","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/RylanYancey/anon-vec"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0039.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-28T06:29:25.817320Z"}}