Affected versions append root to group listings, unless the correct listing has exactly 1024 groups.
This affects both:
If the caller uses this information for access control, this may lead to privilege escalation.
This crate is not currently maintained, so a patched version is not available.
Versions older than 0.8.0 do not contain the affected functions, so downgrading to them is a workaround.
{
"nvd_published_at": null,
"github_reviewed_at": "2025-06-05T01:17:28Z",
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-266"
]
}