VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

384 CVEsRSS

GHSA-chgr-c6px-7xppMedium
3mo ago

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

▾ Sunlitpyo3 · pyo3via GHSA
CVE-2026-48107Medium· 6.5
3mo ago

Russh: Unchecked keyboard-interactive prompt count in client auth path

Russh: Unchecked keyboard-interactive prompt count in client auth path

▾ Sunlitrussh · russhEPSS 0.23%via GHSA
CVE-2026-48108Medium· 5.3
3mo ago

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

▾ Sunlitrussh · russhEPSS 0.28%via GHSA
CVE-2026-48110High· 7.5
3mo ago

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

▾ Twilightrussh · russhEPSS 0.37%via GHSA
RUSTSEC-2026-0175None
3mo ago

`onering` 1.4.1 was removed from crates.io for malicious code

`onering` 1.4.1 was removed from crates.io for malicious code

▾ Sunlitonering · oneringvia OSV
RUSTSEC-2026-0209None
3mo ago

AES-GCM did not enforce limits on AAD length

AES-GCM did not enforce limits on AAD length

▾ Sunlitlibcrux-aesgcm · libcrux-aesgcmvia OSV
CVE-2026-49233High
3mo ago

Routinator has cache path traversal when processing the module component of rsync URIs

Routinator has cache path traversal when processing the module component of rsync URIs

▾ Twilightroutinator · routinatorEPSS 0.45%via GHSA
CVE-2026-49235High
3mo ago

Routinator crashes when encountering maliciously crafted RRDP XML files

Routinator crashes when encountering maliciously crafted RRDP XML files

▾ Twilightroutinator · routinatorEPSS 0.37%via GHSA
CVE-2026-49234High· 7.5
3mo ago

Routinator crashes when sending a maliciously crafted select-asn query parameter

Routinator crashes when sending a maliciously crafted select-asn query parameter

▾ Twilightroutinator · routinatorEPSS 0.27%via GHSA
RUSTSEC-2026-0181None
3mo ago

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

▾ Sunlitvibeio-http · vibeio-httpvia OSV
RUSTSEC-2026-0172None
3mo ago

Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`

Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`

▾ Sunlitdiesel · dieselvia OSV
CVE-2026-47261High· 7.5
3mo ago

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction

▾ Twilightwasmtime-wasi · wasmtime-wasiEPSS 0.36%via OSV
RUSTSEC-2026-0279High· 8.1
3mo ago

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution

▾ Twilightrojo · rojovia OSV
RUSTSEC-2026-0155None
3mo ago

`exploration` was removed from crates.io for malicious code

`exploration` was removed from crates.io for malicious code

▾ Sunlitexploration · explorationvia OSV
CVE-2026-47425Medium
3mo ago

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

rattler has an entry-point path traversal in noarch:python install (arbitrary file write)

▾ Sunlitrattler · rattlerEPSS 0.20%via OSV
CVE-2026-44726High· 7.4
4mo ago

Deno's TLS retry copies stale upgrade hook, risking plaintext traffic

Deno's TLS retry copies stale upgrade hook, risking plaintext traffic

▾ Twilightdeno · denoEPSS 0.23%via OSV
RUSTSEC-2026-0152None
4mo ago

Use-after-free

Use-after-free

▾ Sunlitoneringbuf · oneringbufvia OSV
RUSTSEC-2026-0212None
4mo ago

Potentially Incorrect Output of Constant-Time Swap/Select on Aarch64

Potentially Incorrect Output of Constant-Time Swap/Select on Aarch64

▾ Sunlitlibcrux-secrets · libcrux-secretsvia OSV
RUSTSEC-2026-0208None
4mo ago

Potential Panic in AVX2 SHAKE-256

Potential Panic in AVX2 SHAKE-256

▾ Sunlitlibcrux-sha3 · libcrux-sha3via OSV
CVE-2026-45792Medium· 5.5
4mo ago

RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM

RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM

▾ Sunlitrtk · rtkEPSS 0.11%via OSV
CVE-2026-46428None
4mo ago

TLS hostname verification disabled when using Boring TLS backend

TLS hostname verification disabled when using Boring TLS backend

▾ Sunlitlettre · lettreEPSS 0.32%via OSV
RUSTSEC-2026-0235None
4mo ago

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

▾ Sunlitrkyv · rkyvvia OSV
RUSTSEC-2026-0253None
4mo ago

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

▾ Sunlitlru · lruvia OSV
RUSTSEC-2026-0234None
4mo ago

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

▾ Sunlitrkyv · rkyvvia OSV
RUSTSEC-2026-0233None
4mo ago

Crafted archives can cause a use-after-free during deserialization

Crafted archives can cause a use-after-free during deserialization

▾ Sunlitrkyv · rkyvvia OSV
GHSA-qcxq-75wr-5cm8High
4mo ago

ldap3_proto has LDAP Filter stack exhaustion

ldap3_proto has LDAP Filter stack exhaustion

▾ Twilightldap3_proto · ldap3_protovia OSV
CVE-2026-82254High
4mo ago

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data

▾ Twilightgix-pack · gix-packEPSS 0.35%via OSV
CVE-2026-82252High
4mo ago

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository

▾ Twilightgitoxide · gitoxideEPSS 0.39%via OSV
CVE-2026-82253High
4mo ago

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

▾ Twilightgix · gixEPSS 0.50%via OSV
CVE-2026-82251High
4mo ago

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

▾ Twilightgitoxide · gitoxideEPSS 0.39%via OSV
CVEs tagged “rust” — page 10 · VulnSea