RUSTSEC-2026-0333

Source
https://rustsec.org/advisories/RUSTSEC-2026-0333
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0333.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0333
Aliases
  • GHSA-4xcc-23fx-w2wj
Published
2026-10-06T12:00:00Z
Modified
2026-10-08T15:00:03Z
Summary
Resource budgets not enforced on the typed deserialization path
Details

ParserConfig::max_events, max_nodes, max_total_scalar_bytes, max_merge_keys, alias_anchor_ratio and the alias jump factor were enforced only by the two Value loaders. A typed target with a default-shaped configuration is served by the streaming deserializer, which never read those fields, so tightening any of them had no effect on from_str::<T> for a struct target. The default document-length, depth and alias-count caps were enforced on every path, so no input was unbounded; the gap affects callers who tightened the other budgets for hostile input.

Version 0.0.53 charges every budget on the streaming path as well and adds cross-path parity tests.

Users who cannot upgrade can deserialize into noyalib::Value first and convert with from_value, or rely on max_document_length and max_depth, which were always applied on every path.

Database specific
{
    "license": "CC-BY-4.0"
}
References

Affected packages

crates.io / noyalib

Package

Name
noyalib
View open source insights on deps.dev
Purl
pkg:cargo/noyalib

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.0.53

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "functions": [
            "noyalib::from_reader",
            "noyalib::from_reader_with_config",
            "noyalib::from_slice",
            "noyalib::from_slice_with_config",
            "noyalib::from_str",
            "noyalib::from_str_with_config"
        ],
        "os": []
    }
}

Database specific

categories
[
    "denial-of-service"
]
cvss
null
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0333.json"