CVE-2020-36465: Generic-Array Project Generic-Array

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro to extend lifetimes.

Affected products

  • Generic-Array Project Generic-Array: from 0.8.0, before 0.8.4 (fixed in 0.8.4); from 0.9.0, before 0.9.1 (fixed in 0.9.1); from 0.10.0, before 0.10.1 (fixed in 0.10.1); from 0.11.0, before 0.11.2 (fixed in 0.11.2); from 0.12.0, before 0.12.4 (fixed in 0.12.4); from 0.13.0, before 0.13.3 (fixed in 0.13.3)

Published 2021-08-08. Last modified 2026-06-17.