Low severity3.2NVD Advisory· Published Jul 27, 2025· Updated Jun 17, 2026
CVE-2024-58264
CVE-2024-58264
Description
The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
serde-json-wasmcrates.io | >= 1.0.0, < 1.0.1 | 1.0.1 |
serde-json-wasmcrates.io | < 0.5.2 | 0.5.2 |
Affected products
30+ 1 more
- (no CPE)range: 0
- cpe:2.3:a:cosmwasm:serde-json-wasm:*:*:*:*:*:rust:*:*range: <1.0.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-rr69-rxr6-8qwfnvdThird Party AdvisoryADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-58264ghsaADVISORY
- rustsec.org/advisories/RUSTSEC-2024-0012.htmlnvdThird Party AdvisoryWEB
- crates.io/crates/serde-json-wasmnvdProduct
- github.com/CosmWasm/serde-json-wasm/commit/a9a9b9bf243862bd2afbf6853fca97f30dc4f620ghsaWEB
- github.com/CosmWasm/serde-json-wasm/commit/e78f9e28b3a2151d3175ee88ab2a001bf9515429ghsaWEB
News mentions
0No linked articles in our index yet.