{"data":{"id":"1ce475ec-8af8-4248-a2d7-2991c735beef","title":"GHSA-2jx3-ff3v-j7jj: yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB","summary":"The yara-x library has a vulnerability in its `Rules::deserialize` function, which accepts untrusted data and reconstructs internal lookup tables without validating them. When malformed serialized bytes are passed in, subsequent safe operations like scanning can trigger out-of-bounds memory reads (undefined behavior, unpredictable crashes or memory corruption) because the code uses unsafe operations that assume the internal structures are valid. This means an attacker could craft a malicious serialized rules file to crash or corrupt a program using this library.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-2jx3-ff3v-j7jj","publishedAt":"2026-09-24T19:09:28.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["yara-x@<= 1.18.0 (fixed: 1.19.0)"],"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["VirusTotal","yara-x"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-09-24T19:09:28.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}