Skip to content

Update pyo3 to fix RUSTSEC-2026-0013 (memory corruption) #61

@bug-ops

Description

@bug-ops

Problem

cargo deny check advisories fails due to RUSTSEC-2026-0013 in pyo3 0.28.0.

Vulnerability: Type confusion when accessing data from subclasses of native Python types with abi3 feature targeting Python 3.12+, leading to memory corruption.

Impact: Blocks CI Security Audit job for all PRs (e.g. #60).

Solution

Upgrade pyo3 to >=0.28.2:

cargo update -p pyo3

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions