haohuaijin opened a new issue, #10200:
URL: https://github.com/apache/arrow-rs/issues/10200

   ### Describe the bug
   
   ```
   error: 1 vulnerability found!
   warning: 2 allowed warnings found
   Crate:     quinn-proto
   Version:   0.11.14
   Title:      Remote memory exhaustion in quinn-proto from unbounded 
out-of-order stream reassembly
   Date:      2026-06-22
   ID:        RUSTSEC-2026-0185
   URL:       https://rustsec.org/advisories/RUSTSEC-2026-0185
   Severity:  7.5 (high)
   Solution:  Upgrade to >=0.11.15
   
   Crate:     paste
   Version:   1.0.15
   Warning:   unmaintained
   Title:     paste - no longer maintained
   Date:      2024-10-07
   ID:        RUSTSEC-2024-0436
   URL:       https://rustsec.org/advisories/RUSTSEC-2024-0436
   
   Crate:     memmap2
   Version:   0.9.10
   Warning:   unsound
   Title:     Unchecked pointer offset in crate `memmap2`
   Date:      2026-06-20
   ID:        RUSTSEC-2026-0186
   URL:       https://rustsec.org/advisories/RUSTSEC-2026-0186
   ```
   
   ### To Reproduce
   
   _No response_
   
   ### Expected behavior
   
   _No response_
   
   ### Additional context
   
   find this in 
https://github.com/apache/arrow-rs/actions/runs/28034161797/job/82982788184?pr=10141


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to