GHSA-624c-2h52-gf7f – rosenpass
Package
Manager: cargo
Name: rosenpass
Vulnerable Version: <0
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0: N/A
EPSS: N/A pctlN/A
Details
Duplicate Advisory: Remotely exploitable denial of service in Rosenpass ### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-6ggr-cwv4-g7qg. This link is maintained to preserve external references. ### Original Description The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.
Metadata
Created: 2025-07-28T00:30:34Z
Modified: 2025-07-28T15:08:01Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-624c-2h52-gf7f/GHSA-624c-2h52-gf7f.json
CWE IDs: ["CWE-130"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0