This advisory has been withdrawn because it is a duplicate of GHSA-xvcg-2q82-r87j. This link is maintained to preserve external references.
Affected versions of this crate failed to catch panics crossing FFI boundaries via callbacks, which is a form of UB. This flaw was corrected by [this commit][1] which was included in version 2.6.0.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-248"
],
"nvd_published_at": null,
"github_reviewed_at": "2021-08-18T20:24:24Z",
"github_reviewed": true
}