RUSTSEC-2025-0073

Source
https://rustsec.org/advisories/RUSTSEC-2025-0073
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0073.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2025-0073
Aliases
Published
2025-10-15T12:00:00Z
Modified
2025-10-16T07:42:41Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
DoS vulnerability on `alloy_dyn_abi::TypedData` hashing
Details

An uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash().

Software with high availability requirements such as network services may be particularly impacted. If in use, external auto-restarting mechanisms can partially mitigate the availability issues unless repeated attacks are possible.

The vulnerability was patched by adding a check to ensure the element is not empty before accessing its first element; an error is returned if it is empty. The fix is included in version v1.4.1 and backported to v0.8.26.

There is no known workaround that mitigates the vulnerability. Upgrading to a patched version is the recommended course of action.

Reported by Christian Reitter & Zeke Mostov from Turnkey.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / alloy-dyn-abi

Package

Name
alloy-dyn-abi
View open source insights on deps.dev
Purl
pkg:cargo/alloy-dyn-abi

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.8.26
Introduced
1.0.0
Fixed
1.4.1

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [
            "alloy_dyn_abi::eip712::Resolver::encode_type"
        ],
        "os": []
    }
}

Database specific

categories
[
    "denial-of-service"
]
cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0073.json"