CVE-2020-35864: Google Flatbuffers

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in the flatbuffers crate through 2020-04-11 for Rust. read_scalar (and read_scalar_at) can transmute values without unsafe blocks.

Affected products

  • Google Flatbuffers: from 0.4.0, up to and including 1.12.0

Published 2020-12-31. Last modified 2026-06-17.