Use After Free Affecting rkyv package, versions >=0.8.0-rc.1 <0.8.17


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-RKYV-18748189
  • published13 Aug 2026
  • disclosed11 May 2026
  • creditUnknown

Introduced: 11 May 2026

CVE NOT AVAILABLE CWE-416  (opens in a new tab)

How to fix?

Upgrade rkyv to version 0.8.17 or higher.

Overview

rkyv is a zero-copy deserialization framework for Rust.

Affected versions of this package are vulnerable to Use After Free due to insufficient validation of archive ranges in the deserialize process. An attacker can cause a use-after-free condition by submitting a crafted archive that leads to invalid pointer dereferencing during deserialization of complex data structures.

CVSS Base Scores

version 4.0
version 3.1