MODERATEcrates.io →
SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
Affected packages
- sqlx
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/launchbadge/sqlx/issues/3440
- https://github.com/launchbadge/sqlx
- https://github.com/launchbadge/sqlx/blob/6f2905695b9606b5f51b40ce10af63ac9e696bb8/sqlx-postgres/src/arguments.rs#L163
- https://rustsec.org/advisories/RUSTSEC-2024-0363.html
Structured record: https://osv.dev/vulnerability/GHSA-xmrp-424f-vfpx
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta