CVE-2026-92612: Eclipse Foundation Eclipse Iceoryx
Low severity, CVSS 1.0. EPSS: 0.2% chance of exploitation in the next 30 days.
In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can therefore create an invalid &str and trigger undefined behavior using entirely safe Rust.
Affected products
- Eclipse Foundation Eclipse Iceoryx: from 0.8.1
Published 2026-09-21. Last modified 2026-09-21.