spin-sdk
Spin SDK for Rust
Activity
- Latest release
- 2w ago
- Total releases
- 14
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Downloads
- 195.2k
- Stars
- 35
Details
- License
- Apache-2.0 WITH LLVM-exception
- First release
- Apr 05, 2022
| Version | Released | |
|---|---|---|
7.0.0
major
|
7.0.0
major
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
6.0.0
unknown
|
6.0.0
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.2.0
unknown
|
5.2.0
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
5.1.1
unknown
|
5.1.1
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
5.1.0
unknown
|
5.1.0
unknown
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
5.0.0
unknown
|
5.0.0
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
4.0.0
unknown
|
4.0.0
unknown
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
3.1.1
unknown
|
3.1.1
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.1.0
unknown
|
3.1.0
unknown
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.0.1
unknown
|
3.0.1
unknown
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
3.0.0
unknown
|
3.0.0
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
2.2.0
unknown
1 CVE
CVE-2024-32980
GHSA-f3h7-gpjj-wcvh
May 08, 2024
Spin applications with specific configuration vulnerable to potential network sandbox escape
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactSome specifically configured Spin applications that use If an application's manifest contains a component with configuration such as
and code such as
Then that application can be induced to send an outgoing request to another host (leading the app to process the response assuming it comes from another component in the same application). This can be induced with a request such as
Vulnerable ConfigurationsThe following conditions need to be met for an application to be vulnerable:
If all of these conditions apply, then Spin will use the inbound request's Setups known not to be vulnerableFermyon's Fermyon Cloud serverless product and applications hosted on it are known not to be vulnerable. PatchesHas the problem been patched? What versions should users upgrade to? Spin version 2.4.3 is being released with this advisory going public. WorkaroundsFor deployments of Spin, a workaround is to ensure that the For individual applications, multiple workarounds exist:
Fixed in
2.4.3
References Updated Sep 10, 2026 · Source: OSV.dev |
2.2.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
2.1.0
unknown
1 CVE
CVE-2024-32980
GHSA-f3h7-gpjj-wcvh
May 08, 2024
Spin applications with specific configuration vulnerable to potential network sandbox escape
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactSome specifically configured Spin applications that use If an application's manifest contains a component with configuration such as
and code such as
Then that application can be induced to send an outgoing request to another host (leading the app to process the response assuming it comes from another component in the same application). This can be induced with a request such as
Vulnerable ConfigurationsThe following conditions need to be met for an application to be vulnerable:
If all of these conditions apply, then Spin will use the inbound request's Setups known not to be vulnerableFermyon's Fermyon Cloud serverless product and applications hosted on it are known not to be vulnerable. PatchesHas the problem been patched? What versions should users upgrade to? Spin version 2.4.3 is being released with this advisory going public. WorkaroundsFor deployments of Spin, a workaround is to ensure that the For individual applications, multiple workarounds exist:
Fixed in
2.4.3
References Updated Sep 10, 2026 · Source: OSV.dev |
2.1.0
unknown
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
0.0.0
unknown
yanked
1 CVE
CVE-2024-32980
GHSA-f3h7-gpjj-wcvh
May 08, 2024
Spin applications with specific configuration vulnerable to potential network sandbox escape
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactSome specifically configured Spin applications that use If an application's manifest contains a component with configuration such as
and code such as
Then that application can be induced to send an outgoing request to another host (leading the app to process the response assuming it comes from another component in the same application). This can be induced with a request such as
Vulnerable ConfigurationsThe following conditions need to be met for an application to be vulnerable:
If all of these conditions apply, then Spin will use the inbound request's Setups known not to be vulnerableFermyon's Fermyon Cloud serverless product and applications hosted on it are known not to be vulnerable. PatchesHas the problem been patched? What versions should users upgrade to? Spin version 2.4.3 is being released with this advisory going public. WorkaroundsFor deployments of Spin, a workaround is to ensure that the For individual applications, multiple workarounds exist:
Fixed in
2.4.3
References Updated Sep 10, 2026 · Source: OSV.dev |