---
id: GHSA-6g2r-675j-hx59
title: 'xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release'
summary: 'xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release'
severity: low
cvss: 2.3
cwe:
  - CWE-125
vendor: xxhash-rust
product: xxhash-rust
ecosystem: rust
affected:
  - xxhash-rust < 0.8.16
patched:
  - xxhash-rust 0.8.16
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:29:16Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-6g2r-675j-hx59'
references:
  - url: >-
      https://github.com/DoumanAsh/xxhash-rust/security/advisories/GHSA-6g2r-675j-hx59
  - url: >-
      https://github.com/DoumanAsh/xxhash-rust/commit/200cadb1a442c7f6cd9747e7d4297379b6b74200
  - url: 'https://github.com/advisories/GHSA-6g2r-675j-hx59'
tags:
  - ghsa
  - rust
ingestedAt: '2026-10-02T22:33:09.857Z'
---

## Overview

I have a minimized safe Rust witness for xxhash-rust 0.8.15.

Safe public route:

xxhash_rust::xxh3::xxh3_64_with_secret(&[0x41], &[])

The caller-side harness contains no unsafe code. Under release execution, the internal minimum custom-secret length predicate is enforced only by debug_assert!. Release-Miri reports construction of a fixed-width reference beyond the empty secret allocation.

Observed diagnostic:

Undefined Behavior: constructing invalid value of type &[u8; 4]: encountered a dangling reference

Local repair evidence: handling custom-secret slices shorter than the internal minimum before fixed-width secret reads makes the same safe short-secret harness pass under Linux release-Miri.

Local artifacts:
- vulnerable log: artifacts/logs/W-4332_xxhash_rust_short_secret_miri_release_linux_001.log
- repair log: artifacts/logs/differentials/W-4332_xxhash_rust_local_repair_miri_release_linux_001.log
- report: artifacts/reports/W-4332_xxhash_rust_short_secret_report.md

## Affected packages

- `xxhash-rust < 0.8.16`

## Remediation

Upgrade to a patched release:

- `xxhash-rust 0.8.16`
