Tagged “rust”
CVEs tagged rust, newest first.
386 CVEsRSS
MAL-2025-49350NoneMalicious code in replit_ruspty (crates.io)
Malicious code in replit_ruspty (crates.io)
RUSTSEC-2025-0172None`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead
`zip-extract` is unmaintained; use the `zip >= 2.4.0` crate instead
RUSTSEC-2025-0171Nonesoundness issue
soundness issue
RUSTSEC-2025-0170None`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
RUSTSEC-2025-0169None`FormatContext` stream accessors can cause undefined behavior from safe code
`FormatContext` stream accessors can cause undefined behavior from safe code
CVE-2025-29787Highzip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
CVE-2025-5791High· 7.1users: `root` appended to group listings (CVE-2025-5791)
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in th…
RUSTSEC-2024-0401Medium· 5.3Denial of service because of stack overflow with malicious decompression input
Denial of service because of stack overflow with malicious decompression input
RUSTSEC-2024-0404NoneUnsoundness in anstream
Unsoundness in anstream
CVE-2024-29640Highaliyundrive-webdav vulnerable to Command Injection
aliyundrive-webdav vulnerable to Command Injection
CVE-2024-28854High· 7.5tls-listener affected by the slow loris vulnerability with default configuration
tls-listener affected by the slow loris vulnerability with default configuration
CVE-2024-1410Low· 3.7quiche vulnerable to unbounded storage of information related to connection ID retirement
quiche vulnerable to unbounded storage of information related to connection ID retirement
CVE-2024-1765Medium· 5.9quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
CVE-2021-29511Medium· 6.5Memory over-allocation in evm crate
Memory over-allocation in evm crate
CVE-2023-48795Medium· 5.9PoCPrefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
CVE-2023-6193Medium· 5.3Unbounded queuing of path validation messages in cloudflare-quiche
Unbounded queuing of path validation messages in cloudflare-quiche
CVE-2023-6180Medium· 5.3tokio-boring vulnerable to resource exhaustion via memory leak
tokio-boring vulnerable to resource exhaustion via memory leak
CVE-2023-49092Medium· 5.9Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
MAL-2023-8429NoneMalicious code in littest (crates.io)
Malicious code in littest (crates.io)
CVE-2023-43669High· 7.5Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
RUSTSEC-2023-0085NoneHPACK decoder panics on invalid input
HPACK decoder panics on invalid input
CVE-2023-41880Low· 2.2Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
Miscompilation of wasm `i64x2.shr_s` instruction with constant input on x86_64
CVE-2023-4863High· 8.8CISA KEV0dayPoClibwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
GHSA-jcr6-4frq-9gjjMediumUsers vulnerable to unaligned read of `*const *const c_char` pointer
Users vulnerable to unaligned read of `*const *const c_char` pointer
CVE-2023-4241High· 7.5lol-html panics on certain HTML inputs
lol-html panics on certain HTML inputs
CVE-2023-3766Medium· 5.9odoh-rs's Invalid Slice Split Results in Server Panic
odoh-rs's Invalid Slice Split Results in Server Panic
GHSA-mrrw-grhq-86gfMediumAscii (crate) allows out-of-bounds array indexing in safe code
Ascii (crate) allows out-of-bounds array indexing in safe code
RUSTSEC-2023-0126NoneAliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
CVE-2021-21235Medium· 6.5kamadak-exif vulnerable to Infinite loop when parsing PNG files
kamadak-exif vulnerable to Infinite loop when parsing PNG files
CVE-2021-45707HighOut-of-bounds write in nix::unistd::getgrouplist
Out-of-bounds write in nix::unistd::getgrouplist