yamux
crates.io3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting yamuxpage 1 of 1
- CVE-2024-32984HIGHCVSS 7.5EG 7.5✓ Fixed in 0.13.22024-05-01
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. The Rust implementation of the Yamux stream multiplexer uses a vector for pending frames. This vector is not bounded in length. Every time the Yamux protocol …
- CVE-2026-31814HIGHCVSS 7.5EG 7.5✓ Fixed in 0.13.92026-03-13
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connecti…
- CVE-2026-32314HIGHCVSS 7.5EG 7.5✓ Fixed in 0.13.102026-03-16
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DE…
Check whether yamux is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for yamux CVEs against the assets you own.
Start Free Scan →