Cyber Resilience Act
Gregor Mückl
gregormueckl at gmx.de
Thu Sep 17 09:35:14 UTC 2026
On Wednesday, 16 September 2026 at 15:50:22 UTC, Kagamin wrote:
> Off the top of my head it's unsafe serialization practices (how
> popular are they?) and the -release compiler switch.
It's a bit more than that. Looking at MITRE's CWE Top 25 as an
arbitrary reference [1], I a couple of vulnerability classes that
can be produced in carelessly written D code:
- Out-of-bounds Write
- Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal')
- Use After Free
- Out-of-bounds Read
- Improper Neutralization of Special Elements used in an OS
Command ('OS Command Injection')
- Buffer Copy without Checking Size of Input ('Classic Buffer
Overflow')
- NULL Pointer Dereference
- Stack-based Buffer Overflow
- Heap-based Buffer Overflow
- Improper Neutralization of Special Elements used in a Command
('Command Injection')
Gregor
[1] https://cwe.mitre.org/top25/archive/2025/2025_cwe_top25.html
More information about the Digitalmars-d
mailing list