Tagged “rust”
CVEs tagged rust, newest first.
371 CVEsRSS
RUSTSEC-2026-0296None`unzip` is unmaintained
`unzip` is unmaintained
RUSTSEC-2026-0293NoneDouble free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics
Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics
RUSTSEC-2026-0294NoneUnsoundness in UTF-8 'String' trait
Unsoundness in UTF-8 'String' trait
CVE-2026-93601Low· 2.2rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name
rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…
CVE-2026-93599High· 7.5PoCrustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…
CVE-2026-93602Medium· 4.4rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints
rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…
CVE-2026-93600Low· 2.2rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced
rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…
RUSTSEC-2026-0289Nonepqc_kyber is unmaintained
pqc_kyber is unmaintained
RUSTSEC-2026-0287Nonecosmian_kyber is unmaintained
cosmian_kyber is unmaintained
CVE-2026-68537High· 7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…
CVE-2026-68523High· 7.5`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…
RUSTSEC-2026-0286NoneOut-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
CVE-2026-64684Medium· 6.8RMCP is an official Rust SDK for the Model Context Protocol
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…
CVE-2026-63128High· 7.5PoCRMCP is an official Rust SDK for the Model Context Protocol
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…
CVE-2026-63127High· 8.2PoCRMCP is an official Rust SDK for the Model Context Protocol
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…
CVE-2026-61544High· 8.2PoClibp2p-rust is the official Rust language implementation of the libp2p networking stack
libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…
CVE-2025-24890Medium· 6.8PoCgitoxide is an implementation of git written in Rust
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…
CVE-2026-54541Low· 3.7Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two Trie…
CVE-2026-54542Low· 3.7Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a Tr…
CVE-2026-55832Medium· 6.1PoCTract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…
CVE-2026-55093Medium· 6.1PoCTract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…
RUSTSEC-2026-0283Noneclear_on_drop is unmaintained
clear_on_drop is unmaintained
MAL-2026-16164Critical⚠ ExploitedMalicious code in logs_update (crates.io)
Malicious code in logs_update (crates.io)
GHSA-wfgq-w7cq-qj7jHigh· 7.2mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
GHSA-m3wp-48jr-vr4gHigh· 7.5mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
RUSTSEC-2026-0297None`unzip`: archive extraction is vulnerable to path traversal (zip-slip)
`unzip`: archive extraction is vulnerable to path traversal (zip-slip)
RUSTSEC-2026-0291NoneDouble free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics
Double free in `OwnedAlloc::drop_in_place` when the contained value's `Drop` panics
RUSTSEC-2026-0282NoneDouble free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
CVE-2026-53956Medium· 5.4Rattler vulnerable to package cache path traversal via conda package build string
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…
RUSTSEC-2026-0281None`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code