{"id":"GHSA-v2p5-q653-9j99","summary":"obfstr Type Confusion vulnerability","details":"In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.","aliases":["CVE-2024-58253"],"modified":"2025-05-05T17:44:19.213512Z","published":"2025-05-02T21:30:43Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-05-05T17:25:08Z","nvd_published_at":"2025-05-02T20:15:19Z","cwe_ids":["CWE-843"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58253"},{"type":"WEB","url":"https://github.com/CasualX/obfstr/issues/60"},{"type":"PACKAGE","url":"https://github.com/CasualX/obfstr"},{"type":"WEB","url":"https://github.com/CasualX/obfstr/compare/v0.4.3...v0.4.4"}],"affected":[{"package":{"name":"obfstr","ecosystem":"crates.io","purl":"pkg:cargo/obfstr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-v2p5-q653-9j99/GHSA-v2p5-q653-9j99.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}