Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

RUSTSEC-2026-0317

MediumCVSS 5.5 / 10
Published Sep 29, 2026·Last modified Oct 1, 2026
Affected Components(1)
crates.io logosheets-diff
0.0.0-0 – 3.2.0
Description

Affected versions passed caller-supplied bytes to calamine's Xlsx::new without first checking that they were a ZIP archive. Xlsx::new tests for password protection on its first line, which parses the input as an OLE/CFB container, and a sector-count field read from the file's own header reaches Vec::with_capacity without being checked against the file's actual length. A 512-byte input can therefore request several gigabytes; 9,261,285,372 bytes was measured.

The oversized allocation is always attempted. Whether it aborts depends on what the allocator can satisfy. On a large host with overcommit the reservation is granted untouched and the call returns an ordinary "not an xlsx file" error, which looks like a malformed file being correctly rejected. Under a memory limit the same bytes give memory allocation of N bytes failed and the process aborts, which is not a Result a caller can handle. Containers with a memory limit, small hosts and CI runners are where this lands, so testing on a development machine can wrongly suggest the crate is unaffected.

Every entry point reaches it, not only compare_bytes: the path- and reader-based APIs funnel through the same internal open. Neither Limits::default() nor Limits::hardened() prevents it, because max_input_bytes bounds the length of the input while the allocation's size comes from a field inside it.

Fixed in 3.2.0, which declines input that does not begin with the ZIP magic before the parser sees it, removing the path rather than bounding it. Callers who cannot upgrade can apply the same check before calling this crate.

The underlying defect is in calamine, reported there independently as tafia/calamine#714 and unfixed at the time of writing. It is reachable from any crate that opens untrusted bytes with Xlsx::new.

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
5.5

The vulnerability requires local access to the device to be exploited. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the availability of the system.

Threat Intelligence
5.1

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
N/A

Probability that this vulnerability will be exploited in the wild within the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard