{"id":"GHSA-36hh-v3qg-5jq4","summary":"PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators","details":"PyO3 0.24.0 added optimized implementations of `Iterator::nth` and `DoubleEndedIterator::nth_back` for the `BoundListIterator` and `BoundTupleIterator` types. These implementations computed the target index using unchecked `usize` addition (`index + n`) before bounds-checking against the sequence length, then read the element via `get_item_unchecked`.\n\nIn `nth` methods, a sufficiently large `n` (combined with a non-zero internal index) could cause the addition to overflow and wrap around, producing a small \"target index\" that passed the bounds check and enabling reads at the front of the `list` or `tuple` of elements previously yielded by the iterator.\n\nIn `nth_back` methods, a sufficiently large `n` could cause underflow in a similar fashion, however would instead allow reads of arbitrary memory past the end of the `list` or `tuple` storage.","aliases":["RUSTSEC-2026-0176"],"modified":"2026-09-10T03:51:07.658803617Z","published":"2026-06-12T19:32:47Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-12T19:32:47Z","nvd_published_at":null,"cwe_ids":["CWE-125"]},"references":[{"type":"WEB","url":"https://github.com/PyO3/pyo3/pull/6086"},{"type":"PACKAGE","url":"https://github.com/PyO3/pyo3"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0176.html"}],"affected":[{"package":{"name":"pyo3","ecosystem":"crates.io","purl":"pkg:cargo/pyo3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.29.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-36hh-v3qg-5jq4/GHSA-36hh-v3qg-5jq4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}