RUSTSEC-2022-0054

    Dashboard / Vulnerabilities / RUSTSEC-2022-0054

    RUSTSEC-2022-0054

    Published: 11 May 2022Last Modified: 8 Nov 2023

    Summary: wee_alloc is Unmaintained

    Details: Two of the maintainers have indicated that the crate may not be maintained. The crate has open issues including memory leaks and may not be suitable for production use. It may be best to switch to the default Rust standard allocator on wasm32 targets. Last release seems to have been three years ago. ## Possible Alternative(s) The below list has not been vetted in any way and may or may not contain alternatives; - Rust standard [default allocator] on wasm32-target ## Honorable Mention(s) The below may serve to educate on potential future alternatives: - [lol_alloc](https://crates.io/crates/lol_alloc) [default allocator]: https://github.com/alexcrichton/dlmalloc-rs

    Affected packages

    Package

    Name: wee_alloc

    Purl: pkg:cargo/wee_alloc

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2022-0054 | CVE-DB