CVE-2026-92612
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
| CWE | CWE-749 |
| Vendor | eclipse foundation |
| Product | eclipse iceoryx™ |
| Published | Sep 21, 2026 |
| Last Updated | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse iceoryx™
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse iceoryx™ are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse iceoryx™
0.8.1 ≤ *
References
github.com: https://github.com/eclipse-iceoryx/iceoryx2/security/advisories/GHSA-8mq4-3mwq-qvg6 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/307 github.com: https://github.com/eclipse-iceoryx/iceoryx2/releases/tag/v0.10.0 crates.io: https://crates.io/crates/iceoryx2-bb-container/0.10.0
Credits
https://github.com/hudson-oai