{"id":"GHSA-x57h-xx53-v53w","summary":"stellar-xdr's StringM::from_str bypasses max length validation","details":"### Impact\n\n`StringM::from_str` does not validate that the input length is within the declared maximum (`MAX`). Calling `StringM::\u003cN\u003e::from_str(s)` where `s` is longer than `N` bytes succeeds and returns an `Ok` value instead of `Err(Error::LengthExceedsMax)`, producing a `StringM` that violates its length invariant.\n\nThis affects any code that constructs `StringM` values from string input using `FromStr` (including `str::parse`), and relies on the type's maximum length constraint being enforced. An oversized `StringM` could propagate through serialization, validation, or other logic that assumes the invariant holds.\n\nAll published versions of the `stellar-xdr` crate up to and including `v25.0.0` are affected.\n\n### Patches\n\nThe fix is merged in [#500](https://github.com/stellar/rs-stellar-xdr/pull/500). It replaces the direct `Ok(Self(b))` construction with `b.try_into()`, which routes through `TryFrom\u003cVec\u003cu8\u003e\u003e` and properly validates the length — matching the pattern already used by `BytesM::from_str`.\n\nUsers should upgrade to the first release containing this fix once published (the next release after `v25.0.0`).\n\n### Workarounds\n\nValidate the byte length of string input before calling `StringM::from_str`, or construct `StringM` values via `StringM::try_from(s.as_bytes().to_vec())` which correctly enforces the length constraint.\n\n### References\n\n- Issue: https://github.com/stellar/rs-stellar-xdr/issues/499\n- Fix: https://github.com/stellar/rs-stellar-xdr/pull/500","aliases":["CVE-2026-29795"],"modified":"2026-03-06T23:02:40.557695Z","published":"2026-03-05T20:45:46Z","database_specific":{"cwe_ids":["CWE-770"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-05T20:45:46Z","nvd_published_at":"2026-03-06T21:16:15Z"},"references":[{"type":"WEB","url":"https://github.com/stellar/rs-stellar-xdr/security/advisories/GHSA-x57h-xx53-v53w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29795"},{"type":"WEB","url":"https://github.com/stellar/rs-stellar-xdr/issues/499"},{"type":"WEB","url":"https://github.com/stellar/rs-stellar-xdr/pull/500"},{"type":"WEB","url":"https://github.com/stellar/rs-stellar-xdr/commit/1f840013c3e2fca0321fb844b048afa01d10dda6"},{"type":"PACKAGE","url":"https://github.com/stellar/rs-stellar-xdr"}],"affected":[{"package":{"name":"stellar-xdr","ecosystem":"crates.io","purl":"pkg:cargo/stellar-xdr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"25.0.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 25.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-x57h-xx53-v53w/GHSA-x57h-xx53-v53w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}