141 wires and counting

$ follow Anthropic

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-27
stories 6

© 2026 RepoJournal Home Showcase How it works Privacy

$ the-wire · showcase

buffa closes a JSON recursion bypass, shrinks generated encoders

By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology

The day's real work is in buffa: a raw_value-driven deserialization bypass that let a 2.1 MB body overflow a 38-level stack of nesting, plus a codegen change that cuts compiled binary size on multi-sink encoders.

json: read every object key as data when buffering a value anthropics/buffa

by iainmcgin

When any crate in a build enables serde_json's raw_value feature, serde_json::Value's Deserialize impl treats an object whose first key is $serde_json::private::RawValue as the JSON text under that key, parsed with a fresh recursion limit. buffa buffered untrusted JSON through that impl, so a sender could nest such strings past the 128-level limit and supply a value differing from the request t...

json: read every object key as data when buffering a value (#483) anthropics/buffa

by Iain McGinniss

iainmcgin's change makes buffa read every object key as data when buffering a value, closing the RawValue path at the source rather than only bounding recursion. Treat the two entries as one fix landing on main.

encode: write every BufMut through one pre-sized cursor anthropics/buffa

by iainmcgin

A generated write_to is instantiated once per sink type, so encoding into Vec<u8>, BytesMut, and a Rope carried three copies of every message's write code; buffa now writes every BufMut through one concrete cursor, sharing a single instance per message. On the whatsapp waproto schema (334 messages, 3,477 fields; fat LTO, text + data), a program encoding into three sinks shrinks 6.2% at opt-leve...

fix(reflect): return None for string lookups on non-string maps (#470) anthropics/buffa

by Ruifeng Xue

Yong-yuan-X removed the debug assertion that made MapValue::get_str panic in debug builds on non-string-keyed maps, keeping the allocation-free binary search. Integer- and boolean-keyed maps now return None as documented, including through ReflectMap, with regression coverage for all non-string key variants.

fix(reflect): return None for string lookups on non-string maps anthropics/buffa

by Yong-yuan-X

The same reflect fix tracked as its own pull request, carrying the changelog fragment and the before/after regression test.

Quick answers

What shipped in Anthropic on September 27, 2026?
The day's real work is in buffa: a raw_value-driven deserialization bypass that let a 2.1 MB body overflow a 38-level stack of nesting, plus a codegen change that cuts compiled binary size on multi-sink encoders. In total, 3 commits and 3 pull requests landed.
Who contributed to Anthropic on September 27, 2026?
2 developers shipped this update, including iainmcgin and Ruifeng Xue.
What were the notable Anthropic updates?
json: read every object key as data when buffering a value, json: read every object key as data when buffering a value (#483), and encode: write every BufMut through one pre-sized cursor.