---
id: RUSTSEC-2024-0404
aliases:
  - GHSA-2rxc-gjrp-vjhx
title: Unsoundness in anstream
summary: Unsoundness in anstream
severity: none
vendor: anstream
product: anstream
ecosystem: rust
affected:
  - 'anstream >= 0.0.0-0, < 0.6.8'
patched:
  - anstream 0.6.8
published: '2024-09-08'
updated: '2026-07-17'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2024-0404'
references:
  - url: 'https://crates.io/crates/anstream'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2024-0404.html'
  - url: 'https://github.com/rust-cli/anstyle/issues/156'
tags:
  - osv
  - rust
ingestedAt: '2026-07-17T19:00:51.860Z'
---

## Overview

When given a valid UTF8 string "ö\x1b😀", the function in
crates/anstream/src/adapter/strip.rs will be confused. The UTF8
bytes are \xc3\xb6 then \x1b then \xf0\x9f\x98\x80.

When looping over "non-printable bytes" \x1b\xf0 will be
considered as some non-printable sequence.

This will produce a broken str from the incorrectly segmented
bytes via str::from_utf8_unchecked, and that should never happen.

Full credit goes to [@Ralith](https://github.com/Ralith) who reviewed this code and
asked [@burakemir](https://github.com/burakemir) to follow up.

## Affected packages

- `anstream >= 0.0.0-0, < 0.6.8`

## Remediation

Upgrade to a patched release:

- `anstream 0.6.8`
