This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.

hashbrown known bugs

cargo

2 known bugs in hashbrown, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

2
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
high0.15.00.15.1
Borsh serialization of HashMap is non-canonical
The borsh serialization of the HashMap did not follow the borsh specification. It potentially produced non-canonical encodings dependent on insertion order. It also did not perform canonicty checks on decoding. This can result in consensus splits and cause equivalent objects to be considered distinct. This was patched in 0.15.1.
fixedosv:GHSA-wwq9-3cpr-mm53
medium0.15.00.15.1
Borsh serialization of HashMap is non-canonical
The borsh serialization of the HashMap did not follow the borsh specification. It potentially produced non-canonical encodings dependent on insertion order. It also did not perform canonicty checks on decoding. This can result in consensus splits and cause equivalent objects to be considered distinct. This was patched in 0.15.1.
fixedosv:RUSTSEC-2024-0402
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/cargo/hashbrown
hashbrown bugs — known issues per version | DepScope | DepScope