{"id":"GHSA-9pwq-gcrx-wghh","summary":"Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref","details":"A soundness bug in `buffa`'s `OwnedView\u003cV\u003e` allowed safe Rust code to trigger a use-after-free. The `OwnedView::decode` constructor transmuted a borrowed slice to `&'static [u8]`, and the `Deref` implementation exposed the promoted `'static` lifetime on borrowed view fields (such as `&'static str` and `&'static [u8]`) to callers. Because these references appeared to be `'static`, the borrow checker permitted them to outlive the `OwnedView`; once the `OwnedView` was dropped and its backing buffer freed, those references became dangling, enabling memory corruption, information disclosure of freed heap contents, and cross-thread misuse — all without any `unsafe` code in the calling application. Users are advised to update to the latest patched version of buffa.\n\nThank you to hackerone.com/suul for reporting this issue.","aliases":["CVE-2026-55406"],"modified":"2026-08-28T18:45:07.623595565Z","published":"2026-08-28T18:33:58Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-08-28T18:33:58Z","nvd_published_at":"2026-07-16T17:16:57Z","cwe_ids":["CWE-200","CWE-416"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/anthropics/buffa/security/advisories/GHSA-9pwq-gcrx-wghh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55406"},{"type":"WEB","url":"https://github.com/anthropics/buffa/pull/154"},{"type":"WEB","url":"https://github.com/anthropics/buffa/commit/7dcf50a1a40eca6ed8d6c6dd59f4310aa0d68b0e"},{"type":"PACKAGE","url":"https://github.com/anthropics/buffa"},{"type":"WEB","url":"https://github.com/anthropics/buffa/releases/tag/v0.7.0"}],"affected":[{"package":{"name":"buffa","ecosystem":"crates.io","purl":"pkg:cargo/buffa"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-9pwq-gcrx-wghh/GHSA-9pwq-gcrx-wghh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}