HistoryEditJSON (OSV)

RUSTSEC-2025-0153

hexchat crate is unsound and unmaintained

Reported
Issued
Package
hexchat (crates.io)
Type
INFO Unsound
Categories
Keywords
#memory-safety
References
Patched
no patched versions

Description

All versions of this crate have function deregister_command which can result in use after free. This is unsound.

In addition, all versions since 0.3.0 have "safe" macros, which are documented as unsafe to use in threads.

In addition, the hexchat crate is no longer actively maintained. If you rely on this crate, consider switching to an alternative.

Advisory available under CC0-1.0 license.