🛡️ RUSTSEC-2026-0233 — rkyv
Description
Crafted archives can cause a use-after-free during deserialization
Insufficient archive range validation could allow a crafted archive to reach
ArchivedString::deserialize with an invalid pointer. A reported reproducer
used rkyv::from_bytes to deserialize a struct containing strings, a vector,
a box, and an optional hash map. AddressSanitizer detected a heap use-after-free
during string deserialization.
The flaw could be triggered through the safe checked deserialization API when
processing malicious archive bytes. Version 0.8.17 rejects the malformed
archive during validation. Users who process untrusted archives should upgrade
to 0.8.17 or later.
Affected software
RUSTSEC-2026-0233 is recorded against 1 package.
- rkyv
Timeline and source
Published on 11 May 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
crates.io (Package)
rustsec.org (Advisory)
github.com (Report)
github.com (Web)
github.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| rkyv | — | — |
References
Similar Threats
- Unknown GHSA-vfvv-c25p-m7mm
- Unknown RUSTSEC-2026-0235
- Unknown RUSTSEC-2026-0234
- Unknown RUSTSEC-2026-0122
- Unknown RUSTSEC-2026-0001
More RUSTSEC 2026 advisories
Browse all of RUSTSEC 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by RUSTSEC-2026-0233?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against RUSTSEC-2026-0233 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.