---
id: RUSTSEC-2026-0333
aliases:
  - GHSA-4xcc-23fx-w2wj
title: Resource budgets not enforced on the typed deserialization path
summary: Resource budgets not enforced on the typed deserialization path
severity: none
vendor: noyalib
product: noyalib
ecosystem: rust
affected:
  - 'noyalib >= 0.0.0-0, < 0.0.53'
patched:
  - noyalib 0.0.53
published: '2026-10-06'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:00:03.204356893Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0333'
references:
  - url: 'https://crates.io/crates/noyalib'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0333.html'
  - url: 'https://github.com/sebastienrousseau/noyalib/pull/470'
tags:
  - osv
  - rust
ingestedAt: '2026-10-09T07:36:09.709Z'
---

## Overview

`ParserConfig::max_events`, `max_nodes`, `max_total_scalar_bytes`,
`max_merge_keys`, `alias_anchor_ratio` and the alias jump factor were
enforced only by the two `Value` loaders. A typed target with a
default-shaped configuration is served by the streaming deserializer,
which never read those fields, so tightening any of them had no effect
on `from_str::<T>` for a struct target. The default document-length,
depth and alias-count caps were enforced on every path, so no input was
unbounded; the gap affects callers who tightened the other budgets for
hostile input.

Version 0.0.53 charges every budget on the streaming path as well and
adds cross-path parity tests.

Users who cannot upgrade can deserialize into `noyalib::Value` first and
convert with `from_value`, or rely on `max_document_length` and
`max_depth`, which were always applied on every path.

## Affected packages

- `noyalib >= 0.0.0-0, < 0.0.53`

## Remediation

Upgrade to a patched release:

- `noyalib 0.0.53`
