Affected versions of this crate failed to catch panics crossing FFI boundaries via callbacks, which is a form of UB. This flaw was corrected by [this commit][1] which was included in version 2.6.0.
{
"nvd_published_at": null,
"severity": "MODERATE",
"github_reviewed_at": "2021-08-18T20:24:24Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-248"
]
}