High severity7.3NVD Advisory· Published Apr 1, 2021· Updated Jun 17, 2026
CVE-2021-29935
CVE-2021-29935
Description
An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-provided function panics.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rocketcrates.io | < 0.4.7 | 0.4.7 |
Affected products
3- Rust/rocketdescription
Patches
Vulnerability mechanics
References
6- rustsec.org/advisories/RUSTSEC-2021-0044.htmlnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-vcw4-8ph6-7vw8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-29935ghsaADVISORY
- github.com/SergioBenitez/Rocket/commit/b53a906a8e170fe9b151381c66a76a872c419f9eghsaWEB
- github.com/SergioBenitez/Rocket/commit/e325e2fce4d9f9f392761e9fb58b418a48cef8bbghsaWEB
- github.com/SergioBenitez/Rocket/issues/1534ghsaWEB
News mentions
0No linked articles in our index yet.