Loading vulnerability details...
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-14F82 |
| Severity | HIGH |
| CWE | CWE-476 |
| Confidence | 93% |
| Category | logic_flaw |
| Exploitability | possible |
| Package | servo-url@0.0.0 (cargo) |
| Location | benchmarks/competitors/servo-url/lib.rs:31-34 |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
free_string accepts a *const c_char but does not check for null before converting it back into a CString. Passing a null pointer triggers undefined behavior. Additionally, the function assumes the pointer was allocated by CString::into_raw, leading to possible double‑free if the caller provides an arbitrary pointer.
The vulnerability was identified in the file benchmarks/competitors/servo-url/lib.rs at lines 31-34 within the servo-url package (version 0.0.0). Any code path that invokes these functions inherits this vulnerability.
File: benchmarks/competitors/servo-url/lib.rs (lines 31-34)
let _ = unsafe { std::ffi::CString::from_raw(ptr as *mut _) };
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
An attacker calls free_string(null) via the C API, causing a null‑pointer dereference inside CString::from_raw, which can crash the process or be used to corrupt memory.
Denial of service via process crash; potential memory corruption if misused.
Add a null check at the start of free_string and document that the pointer must have been returned by parse_url_to_href. Optionally, use a safer wrapper that validates the pointer before freeing.
Advisory: SGZ-2026-14F82 | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer.
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-14F82 |
| Severity | HIGH |
| CWE | CWE-476 |
| Confidence | 93% |
| Category | logic_flaw |
| Exploitability | possible |
| Package | servo-url@0.0.0 (cargo) |
| Location | benchmarks/competitors/servo-url/lib.rs:31-34 |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
free_string accepts a *const c_char but does not check for null before converting it back into a CString. Passing a null pointer triggers undefined behavior. Additionally, the function assumes the pointer was allocated by CString::into_raw, leading to possible double‑free if the caller provides an arbitrary pointer.
The vulnerability was identified in the file benchmarks/competitors/servo-url/lib.rs at lines 31-34 within the servo-url package (version 0.0.0). Any code path that invokes these functions inherits this vulnerability.
File: benchmarks/competitors/servo-url/lib.rs (lines 31-34)
let _ = unsafe { std::ffi::CString::from_raw(ptr as *mut _) };
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
An attacker calls free_string(null) via the C API, causing a null‑pointer dereference inside CString::from_raw, which can crash the process or be used to corrupt memory.
Denial of service via process crash; potential memory corruption if misused.
Add a null check at the start of free_string and document that the pointer must have been returned by parse_url_to_href. Optionally, use a safer wrapper that validates the pointer before freeing.
Advisory: SGZ-2026-14F82 | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer. This vulnerability involves weaknesses in
This high-severity vulnerability could allow attackers to gain unauthorized access, execute arbitrary code, or compromise data integrity. Prompt remediation is strongly recommended.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior