Tagged “rust”
CVEs tagged rust, newest first.
384 CVEsRSS
CVE-2026-82253Highgix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
CVE-2026-82251Highgix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
CVE-2026-40034High· 7.8gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
CVE-2026-43868Medium· 5.3Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.
RUSTSEC-2026-0251Nonesized-chunks is unmaintained
sized-chunks is unmaintained
RUSTSEC-2026-0250Noneim-rc is unmaintained
im-rc is unmaintained
RUSTSEC-2026-0249Nonesmartstring is unmaintained
smartstring is unmaintained
RUSTSEC-2026-0248Noneim is unmaintained
im is unmaintained
RUSTSEC-2026-0247Nonebitmaps is unmaintained
bitmaps is unmaintained
CVE-2026-42254HighHickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
MAL-2026-3129NoneMalicious code in supertag (crates.io)
Malicious code in supertag (crates.io)
MAL-2026-3126NoneMalicious code in lsh (crates.io)
Malicious code in lsh (crates.io)
MAL-2026-3103NoneMalicious code in amzn_codewhisperer_streaming_client (crates.io)
Malicious code in amzn_codewhisperer_streaming_client (crates.io)
MAL-2026-3102NoneMalicious code in semantic_search_client (crates.io)
Malicious code in semantic_search_client (crates.io)
MAL-2026-3101NoneMalicious code in amzn_consolas_client (crates.io)
Malicious code in amzn_consolas_client (crates.io)
RUSTSEC-2026-0207NoneIncorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
Incorrect Output of Incremental Portable SHAKE API on Multiple Squeeze Calls
RUSTSEC-2026-0104NoneReachable panic in certificate revocation list parsing
Reachable panic in certificate revocation list parsing
MAL-2026-2958NoneMalicious code in mysten_metrics (crates.io)
Malicious code in mysten_metrics (crates.io)
RUSTSEC-2026-0099NoneName constraints were accepted for certificates asserting a wildcard name
Name constraints were accepted for certificates asserting a wildcard name
RUSTSEC-2026-0098NoneName constraints for URI names were incorrectly accepted
Name constraints for URI names were incorrectly accepted
RUSTSEC-2026-0097NoneRand is unsound with a custom logger using `rand::rng()`
Rand is unsound with a custom logger using `rand::rng()`
RUSTSEC-2026-0273NoneStubbed cryptography without warnings
Stubbed cryptography without warnings
RUSTSEC-2026-0049NoneCRLs not considered authoritative by Distribution Point due to faulty matching logic
CRLs not considered authoritative by Distribution Point due to faulty matching logic
CVE-2026-63762MediumSurrealDB vulnerable to Denial of Service through scripting function memory edge case
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
CVE-2026-63763HighSurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
CVE-2026-23519HighRustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
RUSTSEC-2025-0167None`Bitmap::try_from(&[u8])` can create invalid values
`Bitmap::try_from(&[u8])` can create invalid values
RUSTSEC-2025-0154None`replit_ruspty` was removed from crates.io for malicious code
`replit_ruspty` was removed from crates.io for malicious code
MAL-2025-49350NoneMalicious code in replit_ruspty (crates.io)
Malicious code in replit_ruspty (crates.io)
RUSTSEC-2025-0172None`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead
`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead