highVulnerability

GHSA-47qc-857f-7w7f

PyO3 0.28.1 added support for `#[pyclass(extends=PyList)] struct NativeSub` (and other native types) when targeting Python 3.12 and up with the `abi3` feature. It was discovered that subclasses of such classes would use the type of the subclass when attempting to access to data of `NativeSub` contained within Python objects, amounting to memory corruption. PyO3 0.28.2 fixed the issue by using the type of (e.g.) `NativeSub` correctly.

Properties

ghsa_id
GHSA-47qc-857f-7w7f
severity
high
summary
PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
cve_id
GHSA-47qc-857f-7w7f
is_ghsa_only
true
ghsa_published
2026-02-19T20:25:46Z
source_url
https://github.com/advisories/GHSA-47qc-857f-7w7f
ghsa_updated
2026-02-19T20:25:48Z

Related Entities (3)

AFFECTS (1)

[Software]rust/pyo3

HAS_WEAKNESS (1)

[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph