Tagged “rust”
CVEs tagged rust, newest first.
371 CVEsRSS
RUSTSEC-2026-0280None`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
RUSTSEC-2026-0292NoneDouble free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics
Double free / use-after-free in `Chunk` and `InlineArray` removal methods when an element's `Drop` panics
CVE-2026-63733Medium· 4.3SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
CVE-2026-63735High· 8.1SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
CVE-2026-53600Mediumasync-tar is a tar archive reading/writing library for async Rust
async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) …
CVE-2026-78422None`zbus_polkit`: authorization bypass via PID reuse
`zbus_polkit`: authorization bypass via PID reuse
CVE-2026-82250Medium· 6.5gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
CVE-2026-55406MediumBuffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
CVE-2026-55407MediumBuffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
CVE-2026-54788High· 7.5dd-trace-rs provides Datadog application performance monitoring for Rust
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value…
GHSA-2vh6-hw4j-32wwMedium· 6.5gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
RUSTSEC-2026-0272NonePanic-safety unsoundness in `Stack::pop`, `Fifo::pop_front` and `Value::replace_stable` (use-after-free / double-free)
Panic-safety unsoundness in `Stack::pop`, `Fifo::pop_front` and `Value::replace_stable` (use-after-free / double-free)
RUSTSEC-2026-0284NoneDouble free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`
Double free in `Map::into_iter` and an uninitialized `Arc` in `SharedIncin::clear`
RUSTSEC-2026-0277NonePath traversal in apimock-server's file-serving fallback
Path traversal in apimock-server's file-serving fallback
RUSTSEC-2026-0276NonePath traversal in apimock's file-serving fallback
Path traversal in apimock's file-serving fallback
CVE-2026-46369High· 7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative t…
RUSTSEC-2026-0267NonePanic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
GHSA-fx4f-mhw4-qm7jMediumvibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
GHSA-5x78-73v4-xg6wHighpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-rgqc-3x5p-6gwgMediumpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
GHSA-3gjw-f78c-vvpwMediumtokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
CVE-2026-53530HighRaTeX is a KaTeX-compatible math rendering engine written in Rust
RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter …
CVE-2026-53531MediumRaTeX is a KaTeX-compatible math rendering engine written in Rust
RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximu…
CVE-2026-63481MediumHurl is a command line tool that runs and tests HTTP requests defined in plain text files
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth cre…
RUSTSEC-2026-0269NoneFilesystem sandbox escape when paths or symlinks contain trailing slashes
Filesystem sandbox escape when paths or symlinks contain trailing slashes
RUSTSEC-2026-0268NoneGuest controlled-size host heap allocation through WASIp3 streams
Guest controlled-size host heap allocation through WASIp3 streams
MAL-2026-14340NoneMalicious code in tinymember (crates.io)
Malicious code in tinymember (crates.io)
MAL-2026-14339NoneMalicious code in proc_macro_en (crates.io)
Malicious code in proc_macro_en (crates.io)
MAL-2026-14338NoneMalicious code in proc_macro1 (crates.io)
Malicious code in proc_macro1 (crates.io)
MAL-2026-14337NoneMalicious code in internment (crates.io)
Malicious code in internment (crates.io)