lowCVSS 2.3Vulnerability

GHSA-6g2r-675j-hx59

I have a minimized safe Rust witness for xxhash-rust 0.8.15. Safe public route: xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[]) The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation. Observed diagnostic: Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri. Local artifacts: - vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log - repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log - report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md

Properties

severity
low
summary
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
cvss_score
2.3
retrieved_at
2026-10-02T19:33:52+00:00
ghsa_published
2026-10-02T18:29:13Z
source_url
https://github.com/advisories/GHSA-6g2r-675j-hx59
ghsa_updated
2026-10-02T18:29:16Z
ghsa_id
GHSA-6g2r-675j-hx59
last_source
GitHub Advisory Database
cve_id
GHSA-6g2r-675j-hx59
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
signal_observed_at
2026-10-02T19:33:52+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]rust/xxhash-rust

AFFECTS (1)

→[Software]rust/xxhash-rust

HAS_WEAKNESS (1)

→[Weakness]Out-of-bounds Read

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6g2r-675j-hx59 (CVSS 2.3) — Ninja Signal Threat Intelligence | Ninja Signal