RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0333

Resource budgets not enforced on the typed deserialization path

Reported
Issued
Package
noyalib (crates.io)
Type
Vulnerability
Categories
Keywords
#yaml #resource-exhaustion #budget
Aliases
References
Patched
  • >=0.0.53
Affected Functions
Version
noyalib::from_reader
  • <0.0.53
noyalib::from_reader_with_config
  • <0.0.53
noyalib::from_slice
  • <0.0.53
noyalib::from_slice_with_config
  • <0.0.53
noyalib::from_str
  • <0.0.53
noyalib::from_str_with_config
  • <0.0.53

Description

ParserConfig::max_events, max_nodes, max_total_scalar_bytes, max_merge_keys, alias_anchor_ratio and the alias jump factor were enforced only by the two Value loaders. A typed target with a default-shaped configuration is served by the streaming deserializer, which never read those fields, so tightening any of them had no effect on from_str::<T> for a struct target. The default document-length, depth and alias-count caps were enforced on every path, so no input was unbounded; the gap affects callers who tightened the other budgets for hostile input.

Version 0.0.53 charges every budget on the streaming path as well and adds cross-path parity tests.

Users who cannot upgrade can deserialize into noyalib::Value first and convert with from_value, or rely on max_document_length and max_depth, which were always applied on every path.

Advisory available under CC-BY-4.0 license. Source: https://github.com/sebastienrousseau/noyalib/pull/470