{"id":"RUSTSEC-2026-0333","aliases":["GHSA-4xcc-23fx-w2wj"],"title":"Resource budgets not enforced on the typed deserialization path","summary":"Resource budgets not enforced on the typed deserialization path","severity":"none","vendor":"noyalib","product":"noyalib","ecosystem":"rust","affected":["noyalib >= 0.0.0-0, < 0.0.53"],"patched":["noyalib 0.0.53"],"published":"2026-10-06","updated":"2026-10-08","sourceUpdated":"2026-10-08T15:00:03.204356893Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0333","references":[{"url":"https://crates.io/crates/noyalib"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0333.html"},{"url":"https://github.com/sebastienrousseau/noyalib/pull/470"}],"tags":["osv","rust"],"ingestedAt":"2026-10-09T07:36:09.709Z","slug":"RUSTSEC-2026-0333","body":"## Overview\n\n`ParserConfig::max_events`, `max_nodes`, `max_total_scalar_bytes`,\n`max_merge_keys`, `alias_anchor_ratio` and the alias jump factor were\nenforced only by the two `Value` loaders. A typed target with a\ndefault-shaped configuration is served by the streaming deserializer,\nwhich never read those fields, so tightening any of them had no effect\non `from_str::<T>` for a struct target. The default document-length,\ndepth and alias-count caps were enforced on every path, so no input was\nunbounded; the gap affects callers who tightened the other budgets for\nhostile input.\n\nVersion 0.0.53 charges every budget on the streaming path as well and\nadds cross-path parity tests.\n\nUsers who cannot upgrade can deserialize into `noyalib::Value` first and\nconvert with `from_value`, or rely on `max_document_length` and\n`max_depth`, which were always applied on every path.\n\n## Affected packages\n\n- `noyalib >= 0.0.0-0, < 0.0.53`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `noyalib 0.0.53`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}