VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

384 CVEsRSS

CVE-2026-82253High
4mo ago

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure

▾ Twilightgix · gixEPSS 0.50%via OSV
CVE-2026-82251High
4mo ago

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository

▾ Twilightgitoxide · gitoxideEPSS 0.39%via OSV
CVE-2026-40034High· 7.8
4mo ago

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

▾ Twilightgix · gixEPSS 0.35%via OSV
CVE-2026-43868Medium· 5.3
4mo ago

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

▾ Sunlitapache · thriftEPSS 0.71%via NVD
RUSTSEC-2026-0251None
4mo ago

sized-chunks is unmaintained

sized-chunks is unmaintained

▾ Sunlitsized-chunks · sized-chunksvia OSV
RUSTSEC-2026-0250None
4mo ago

im-rc is unmaintained

im-rc is unmaintained

▾ Sunlitim-rc · im-rcvia OSV
RUSTSEC-2026-0249None
4mo ago

smartstring is unmaintained

smartstring is unmaintained

▾ Sunlitsmartstring · smartstringvia OSV
RUSTSEC-2026-0248None
4mo ago

im is unmaintained

im is unmaintained

▾ Sunlitim · imvia OSV
RUSTSEC-2026-0247None
4mo ago

bitmaps is unmaintained

bitmaps is unmaintained

▾ Sunlitbitmaps · bitmapsvia OSV
CVE-2026-42254High
4mo ago

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation

▾ Twilighthickory-recursor · hickory-recursorEPSS 0.16%via OSV
MAL-2026-3129None
5mo ago

Malicious code in supertag (crates.io)

Malicious code in supertag (crates.io)

▾ Sunlitsupertag · supertagvia OSV
MAL-2026-3126None
5mo ago

Malicious code in lsh (crates.io)

Malicious code in lsh (crates.io)

▾ Sunlitlsh · lshvia OSV
MAL-2026-3103None
5mo ago

Malicious code in amzn_codewhisperer_streaming_client (crates.io)

Malicious code in amzn_codewhisperer_streaming_client (crates.io)

▾ Sunlitamzn-codewhisperer-streaming-client · amzn-codewhisperer-streaming-clientvia OSV
MAL-2026-3102None
5mo ago

Malicious code in semantic_search_client (crates.io)

Malicious code in semantic_search_client (crates.io)

▾ Sunlitsemantic-search-client · semantic-search-clientvia OSV
MAL-2026-3101None
5mo ago

Malicious code in amzn_consolas_client (crates.io)

Malicious code in amzn_consolas_client (crates.io)

▾ Sunlitamzn-consolas-client · amzn-consolas-clientvia OSV
RUSTSEC-2026-0207None
5mo ago

Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls

Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls

▾ Sunlitlibcrux-sha3 · libcrux-sha3via OSV
RUSTSEC-2026-0104None
5mo ago

Reachable panic in certificate revocation list parsing

Reachable panic in certificate revocation list parsing

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
MAL-2026-2958None
5mo ago

Malicious code in mysten_metrics (crates.io)

Malicious code in mysten_metrics (crates.io)

▾ Sunlitmysten-metrics · mysten-metricsvia OSV
RUSTSEC-2026-0099None
5mo ago

Name constraints were accepted for certificates asserting a wildcard name

Name constraints were accepted for certificates asserting a wildcard name

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0098None
5mo ago

Name constraints for URI names were incorrectly accepted

Name constraints for URI names were incorrectly accepted

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
RUSTSEC-2026-0097None
5mo ago

Rand is unsound with a custom logger using `rand::rng()`

Rand is unsound with a custom logger using `rand::rng()`

▾ Sunlitrand · randvia OSV
RUSTSEC-2026-0273None
5mo ago

Stubbed cryptography without warnings

Stubbed cryptography without warnings

▾ Sunlitmanzana · manzanavia OSV
RUSTSEC-2026-0049None
6mo ago

CRLs not considered authoritative by Distribution Point due to faulty matching logic

CRLs not considered authoritative by Distribution Point due to faulty matching logic

▾ Sunlitrustls-webpki · rustls-webpkivia OSV
CVE-2026-63762Medium
7mo ago

SurrealDB vulnerable to Denial of Service through scripting function memory edge case

SurrealDB vulnerable to Denial of Service through scripting function memory edge case

▾ Sunlitsurrealdb · surrealdbEPSS 0.45%via OSV
CVE-2026-63763High
8mo ago

SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions

SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions

▾ Twilightsurrealdb · surrealdbEPSS 0.50%via OSV
CVE-2026-23519High
8mo ago

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

▾ Twilightcmov · cmovEPSS 0.57%via OSV
RUSTSEC-2025-0167None
9mo ago

`Bitmap::try_from(&[u8])` can create invalid values

`Bitmap::try_from(&[u8])` can create invalid values

▾ Sunlitbitmaps · bitmapsvia OSV
RUSTSEC-2025-0154None
10mo ago

`replit_ruspty` was removed from crates.io for malicious code

`replit_ruspty` was removed from crates.io for malicious code

▾ Sunlitreplit_ruspty · replit_rusptyvia OSV
MAL-2025-49350None
10mo ago

Malicious code in replit_ruspty (crates.io)

Malicious code in replit_ruspty (crates.io)

▾ Sunlitreplit_ruspty · replit_rusptyvia OSV
RUSTSEC-2025-0172None
1y ago

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead

▾ Sunlitzip-extract · zip-extractvia OSV
CVEs tagged “rust” — page 11 · VulnSea