Vulnerability DatabaseGHSA-8327-84cj-8xjm

GHSA-8327-84cj-8xjm
Rust vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-8327-84cj-8xjm) affects the alloy-json-abi Rust crate versions 0.7.7 and earlier, where improper handling of malformatted JSON ABI strings could lead to a stack overflow condition. The issue was discovered on July 30, 2024, and was officially disclosed on August 15, 2024. The vulnerability affects the JsonAbi::parse method when processing specially crafted input (GitHub Advisory, RustSec Advisory).

Technical details

The vulnerability stems from the JsonAbi::parse method's inability to properly handle deeply nested parentheses in malformed JSON ABI strings. The issue manifests as a stack overflow condition when processing specially crafted input that contains excessive recursive structures. The vulnerability has been assigned a CVSS v4.0 score of 6.9 (Moderate severity), with the following metrics: Attack Vector: Network, Attack Complexity: Low, Attack Requirements: None, Privileges Required: None, User Interaction: None (GitHub Advisory).

Impact

When successfully exploited, this vulnerability can cause a crash of the application using the alloy-json-abi crate, resulting in a denial of service condition. The impact is primarily limited to availability, with no direct effects on confidentiality or integrity of the system (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in commit 4790c47 of the alloy-rs/core repository. However, there is currently no patched version available. Users are advised to monitor for updates and implement input validation measures to prevent processing of deeply nested JSON ABI strings (RustSec Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-2fjw-whxm-9v4qCRITICAL9.3
  • RustRust
  • nftnl
NoYesNov 25, 2025
CVE-2025-66017HIGH8.2
  • RustRust
  • cggmp21
NoYesNov 25, 2025
GHSA-mj73-j457-8x9qLOW2.7
  • RustRust
  • maxminddb
NoYesDec 02, 2025
GHSA-pq5v-rwp8-p7gmLOW2.7
  • RustRust
  • rtvm-interpreter
NoNoDec 02, 2025
RUSTSEC-2025-0132N/AN/A
  • RustRust
  • maxminddb
NoYesNov 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management