Tagged “rust”
CVEs tagged rust, newest first.
384 CVEsRSS
GHSA-chgr-c6px-7xppMediumPyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
CVE-2026-48107Medium· 6.5Russh: Unchecked keyboard-interactive prompt count in client auth path
Russh: Unchecked keyboard-interactive prompt count in client auth path
CVE-2026-48108Medium· 5.3Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
CVE-2026-48110High· 7.5Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
RUSTSEC-2026-0175None`onering` 1.4.1 was removed from crates.io for malicious code
`onering` 1.4.1 was removed from crates.io for malicious code
RUSTSEC-2026-0209NoneAES-GCM did not enforce limits on AAD length
AES-GCM did not enforce limits on AAD length
CVE-2026-49233HighRoutinator has cache path traversal when processing the module component of rsync URIs
Routinator has cache path traversal when processing the module component of rsync URIs
CVE-2026-49235HighRoutinator crashes when encountering maliciously crafted RRDP XML files
Routinator crashes when encountering maliciously crafted RRDP XML files
CVE-2026-49234High· 7.5Routinator crashes when sending a maliciously crafted select-asn query parameter
Routinator crashes when sending a maliciously crafted select-asn query parameter
RUSTSEC-2026-0181NoneDoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
RUSTSEC-2026-0172NonePossible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
CVE-2026-47261High· 7.5wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
RUSTSEC-2026-0279High· 8.1Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
RUSTSEC-2026-0155None`exploration` was removed from crates.io for malicious code
`exploration` was removed from crates.io for malicious code
CVE-2026-47425Mediumrattler has an entry-point path traversal in noarch:python install (arbitrary file write)
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
CVE-2026-44726High· 7.4Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
RUSTSEC-2026-0152NoneUse-after-free
Use-after-free
RUSTSEC-2026-0212NonePotentially Incorrect Output of Constant-Time Swap/Select on Aarch64
Potentially Incorrect Output of Constant-Time Swap/Select on Aarch64
RUSTSEC-2026-0208NonePotential Panic in AVX2 SHAKE-256
Potential Panic in AVX2 SHAKE-256
CVE-2026-45792Medium· 5.5RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
CVE-2026-46428NoneTLS hostname verification disabled when using Boring TLS backend
TLS hostname verification disabled when using Boring TLS backend
RUSTSEC-2026-0235NoneInsufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
RUSTSEC-2026-0253NonePotential use-after-free due to lack of panic safety in `LruCache::pop()`
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
RUSTSEC-2026-0234NoneInsufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
RUSTSEC-2026-0233NoneCrafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization
GHSA-qcxq-75wr-5cm8Highldap3_proto has LDAP Filter stack exhaustion
ldap3_proto has LDAP Filter stack exhaustion
CVE-2026-82254Highgix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
CVE-2026-82252Highgix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
CVE-2026-82253Highgix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
CVE-2026-82251Highgix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository