Vulnerability GHSA-6g2r-675j-hx59

Low Risk
LOW RISK
CVSS Score: 2.3
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
5 hours ago
October 02, 2026 at 06:29 PM UTC
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
0.8.0 - 0.8.15
0.8.0 - 0.8.15

Summary

xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release

Details

I have a minimized safe Rust witness for xxhash-rust 0.8.15.

Safe public route:

xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[])

The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.

Observed diagnostic:

Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference

Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.

Local artifacts:

  • vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log
  • repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log
  • report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md

Impacted packages

Timeline

Published
5 hours ago
October 02, 2026 at 06:29 PM UTC
Fixed (0.8.16)
3 months ago
July 01, 2026 at 01:13 PM UTC
Last Modified
5 hours ago
October 02, 2026 at 06:45 PM UTC