unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches.
References
| Link | Resource |
|---|---|
| https://github.com/spearman/unbounded-spsc/security/advisories/GHSA-6m57-8r3p-pqx6 | Exploit Vendor Advisory |
| https://github.com/spearman/unbounded-spsc/security/advisories/GHSA-6m57-8r3p-pqx6 | Exploit Vendor Advisory |
Configurations
History
16 Jun 2026, 00:07
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Spearman
Spearman unbounded-spsc |
|
| CPE | cpe:2.3:a:spearman:unbounded-spsc:*:*:*:*:*:*:*:* | |
| References | () https://github.com/spearman/unbounded-spsc/security/advisories/GHSA-6m57-8r3p-pqx6 - Exploit, Vendor Advisory |
12 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/spearman/unbounded-spsc/security/advisories/GHSA-6m57-8r3p-pqx6 - |
12 Jun 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 16:16
Updated : 2026-06-17 10:53
NVD link : CVE-2026-46690
Mitre link : CVE-2026-46690
CVE.ORG link : CVE-2026-46690
JSON object : View
Products Affected
spearman
- unbounded-spsc
