highVulnerability
GHSA-47qc-857f-7w7f
PyO3 0.28.1 added support for `#[pyclass(extends=PyList)] struct NativeSub` (and other native types) when targeting Python 3.12 and up with the `abi3` feature. It was discovered that subclasses of such classes would use the type of the subclass when attempting to access to data of `NativeSub` contained within Python objects, amounting to memory corruption. PyO3 0.28.2 fixed the issue by using the type of (e.g.) `NativeSub` correctly.
Properties
- ghsa_id
- GHSA-47qc-857f-7w7f
- severity
- high
- summary
- PyO3 has type confusion when accessing data from sublasses of subclasses of native types with `abi3` feature
- cve_id
- GHSA-47qc-857f-7w7f
- is_ghsa_only
- true
- ghsa_published
- 2026-02-19T20:25:46Z
- source_url
- https://github.com/advisories/GHSA-47qc-857f-7w7f
- ghsa_updated
- 2026-02-19T20:25:48Z
Related Entities (3)
AFFECTS (1)
→[Software]rust/pyo3
HAS_WEAKNESS (1)
→[Weakness]Access of Resource Using Incompatible Type ('Type Confusion')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph