cargo package report

Is iceoryx2-bb-container safe?

1 known vulnerability.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.


      cvss
      not scored

      severity out of 10

      epss
      not scored

      chance of exploitation in 30 days

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-8mq4-3mwq-qvg6, the advisory selected below

      // 1 advisories

      GHSA-8mq4-3mwq-qvg6

      UNKNOWN

      The String API in iceoryx2-bb-container exposes its contents as mutable bytes through safe APIs, while String::asstr() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.

      The API methods asmutbytes and derefmut where removed from the String API and their implementations (PolymorphicString, RelocatableString, and StaticString ) without replacement. Link to Pull-Request: https://github.com/eclipse-iceoryx/iceoryx2/pull/1956


      Checked 2026-09-23 at 07:51 UTC. The most recent advisory here was published 2026-09-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.
      Is iceoryx2-bb-container safe? cargo package security report | CyberXYZ