In version 0.0.4, libyml::string::yaml_string_extend
was revised resulting in undefined behaviour, which is unsound.
The GitHub project for libyml
was archived after unsoundness issues were raised.
If you rely on this crate, it is highly recommended switching to a maintained alternative.
unsafe-libyaml
{ "github_reviewed": true, "severity": "HIGH", "nvd_published_at": null, "cwe_ids": [ "CWE-758" ], "github_reviewed_at": "2025-09-15T13:57:29Z" }