{"id":"GHSA-w65j-g6c7-g3m4","summary":"Multiple memory safety issues in actix-web","details":"Affected versions contain multiple memory safety issues, such as:\n\n - Unsoundly coercing immutable references to mutable references\n - Unsoundly extending lifetimes of strings\n - Adding the `Send` marker trait to objects that cannot be safely sent between threads\n\nThis may result in a variety of memory corruption scenarios, most likely use-after-free.\n \nA signficant refactoring effort has been conducted to resolve these issues.","aliases":["CVE-2018-25024","CVE-2018-25025","CVE-2018-25026","GHSA-7x36-h62w-vw65","GHSA-9qj6-4rfq-vm84","GHSA-fgfm-hqjw-3265","RUSTSEC-2018-0019"],"modified":"2026-06-09T11:00:13.794544779Z","published":"2021-08-25T20:42:50Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-08-24T19:13:30Z","nvd_published_at":null,"cwe_ids":["CWE-362"]},"references":[{"type":"WEB","url":"https://github.com/actix/actix-web/issues/289"},{"type":"PACKAGE","url":"https://github.com/actix/actix-web"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2018-0019.html"}],"affected":[{"package":{"name":"actix-web","ecosystem":"crates.io","purl":"pkg:cargo/actix-web"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.7.19"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-w65j-g6c7-g3m4/GHSA-w65j-g6c7-g3m4.json"}}],"schema_version":"1.9.0"}