PT-2026-76522 · Crates.Io · Dcrypt-Api

Published

2026-08-09

·

Updated

2026-08-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
All published versions of dcrypt-api before 2.0.0 exposed safe ErrorRegistry operations that could trigger undefined behavior when the default std feature was enabled.
Stored Box<E> values were erased to raw pointers and later deallocated as Box<()>. The get error<E> operation also performed an unchecked cast to a caller-selected type. Finally, concurrent replacement or clearing could free a value while another thread cloned it. Ordinary safe Rust could therefore cause mismatched deallocation, type confusion, and use-after-free. Crates that re-exported this API are affected transitively.
Version 2.0.0 replaces the raw pointers with owned Box<dyn Any + Send> values behind a mutex, performs checked downcasts, and uses a mutation generation so concurrent stores and clears win safely. There is no reliable workaround while calling the affected registry API. Upgrade to 2.0.0 or later and avoid process-global error state where possible.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0242

Affected Products

Dcrypt-Api