Vulnerability DatabaseRUSTSEC-2023-0035

RUSTSEC-2023-0035
Rust vulnerability analysis and mitigation

Overview

RUSTSEC-2023-0035 affects the enumflags2 Rust crate, specifically related to a soundness issue in the make_bitflags! macro. The vulnerability was introduced in version 0.7.0 and affects all versions up to 0.7.7. The issue allows adversarial use of the make_bitflags! macro to cause undefined behavior (GitHub Release).

Technical details

The vulnerability exists in the make_bitflags! macro implementation where it incorrectly accepts code that can create invalid bit patterns. For example, when using a constant value outside the defined enum variants within the macro, it could generate values of the enum with bit patterns that don't correspond to any valid variants, leading to undefined behavior when iterating over these values (GitHub Release).

Impact

When exploited, this vulnerability can lead to undefined behavior in Rust programs using the affected versions of enumflags2. The impact is particularly concerning as it breaks Rust's safety guarantees by allowing the creation of invalid enum values (GitHub Release).

Mitigation and workarounds

The issue has been fixed in version 0.7.7 of the enumflags2 crate. All affected versions (0.7.0 through 0.7.6) have been yanked from the registry. Users should upgrade to version 0.7.7 or later to receive the fix (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47128MEDIUM6.1
  • Rust logoRust
  • nono-cli
NoYesJul 20, 2026
CVE-2026-47144MEDIUM5.5
  • JavaScript logoJavaScript
  • shamefile
NoYesJul 20, 2026
CVE-2026-48504MEDIUM5.3
  • Rust logoRust
  • deno
NoYesJul 17, 2026
CVE-2026-45784MEDIUM5.1
  • Rust logoRust
  • sentry-cli
NoYesJul 17, 2026
CVE-2026-46671MEDIUM4.4
  • Rust logoRust
  • onenote_parser
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management