Cyber Resilience Act

Gregor Mückl gregormueckl at gmx.de
Thu Sep 17 09:35:14 UTC 2026


On Wednesday, 16 September 2026 at 15:50:22 UTC, Kagamin wrote:
> Off the top of my head it's unsafe serialization practices (how 
> popular are they?) and the -release compiler switch.

It's a bit more than that. Looking at  MITRE's CWE Top 25 as an 
arbitrary reference [1], I a couple of vulnerability classes that 
can be produced in carelessly written D code:

- Out-of-bounds Write
- Improper Limitation of a Pathname to a Restricted Directory 
('Path Traversal')
- Use After Free
- Out-of-bounds Read
- Improper Neutralization of Special Elements used in an OS 
Command ('OS Command Injection')
- Buffer Copy without Checking Size of Input ('Classic Buffer 
Overflow')
- NULL Pointer Dereference
- Stack-based Buffer Overflow
- Heap-based Buffer Overflow
- Improper Neutralization of Special Elements used in a Command 
('Command Injection')

Gregor

[1] https://cwe.mitre.org/top25/archive/2025/2025_cwe_top25.html



More information about the Digitalmars-d mailing list