🔐 CVE Alert

CVE-2026-92612

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.

CWE CWE-749
Vendor eclipse foundation
Product eclipse iceoryx™
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse iceoryx™

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse iceoryx™ are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse iceoryx™
0.8.1 ≤ *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/eclipse-iceoryx/iceoryx2/security/advisories/GHSA-8mq4-3mwq-qvg6 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/307 github.com: https://github.com/eclipse-iceoryx/iceoryx2/releases/tag/v0.10.0 crates.io: https://crates.io/crates/iceoryx2-bb-container/0.10.0

Credits

https://github.com/hudson-oai