Vulnerability DatabaseRUSTSEC-2024-0369

RUSTSEC-2024-0369
Rust vulnerability analysis and mitigation

Overview

A high severity vulnerability (RUSTSEC-2024-0369) was discovered in the rust-phonenumber package affecting versions >= 0.3.4 and < 0.3.6. The vulnerability was disclosed on July 9, 2024, and involves a potential panic in the phonenumber parsing code when processing specially crafted inputs (GitHub Advisory).

Technical details

The vulnerability stems from a reachable assert! guard on the phonenumber string processing. The issue specifically occurs when parsing strings formatted as '+dwPAA;phone-context=AA', where the 'number' part potentially parses as a number larger than 2^56. The vulnerability has been assigned a CVSS score of 8.6 (High), with attack vector being Network, attack complexity Low, requiring no privileges or user interaction, and affecting system availability (GitHub Advisory).

Impact

The primary impact of this vulnerability is on system availability. When successfully exploited, it can cause the application to panic, potentially leading to denial of service. The vulnerability has no direct impact on confidentiality or integrity of the system (GitHub Advisory).

Exploitability

The vulnerability can be exploited remotely by sending maliciously crafted phone numbers over the network. The attack complexity is considered low, requiring no special privileges or user interaction. A proof-of-concept exploit exists using the string pattern '+dwPAA;phone-context=AA' (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 0.3.6 and later releases. Users are advised to upgrade to version 0.3.6 or higher. No alternative workarounds are available (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-mc9m-6fm9-pghcMEDIUM6.9
  • Python logoPython
  • zoo-kcl
NoYesAug 20, 2026
GHSA-jgvr-6x5w-hx5wMEDIUM6.9
  • Python logoPython
  • zoo-kcl
NoYesAug 20, 2026
CVE-2026-54136MEDIUM5.1
  • Rust logoRust
  • windmill-api
NoYesAug 20, 2026
RUSTSEC-2026-0266NONEN/A
  • Rust logoRust
  • internment
NoYesAug 20, 2026
RUSTSEC-2026-0265NONEN/A
  • Rust logoRust
  • proc-macro1
NoNoAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management