An issue was discovered in the arr crate through 2020-08-25 for Rust. An attacker can smuggle non-Sync/Send types across a thread boundary to cause a data race.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35886.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "2020-08-25" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "2020-08-25" } ] } ]