VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

372 CVEsRSS

MAL-2026-14337None
1mo ago

Malicious code in internment (crates.io)

Malicious code in internment (crates.io)

Sunlitinternment · internmentvia OSV
MAL-2026-14336None
1mo ago

Malicious code in arrayref (crates.io)

Malicious code in arrayref (crates.io)

Sunlitarrayref · arrayrefvia OSV
MAL-2026-14335None
1mo ago

Malicious code in aronenao (crates.io)

Malicious code in aronenao (crates.io)

Sunlitaronenao · aronenaovia OSV
MAL-2026-14334None
1mo ago

Malicious code in arone (crates.io)

Malicious code in arone (crates.io)

Sunlitarone · aronevia OSV
MAL-2026-14333None
1mo ago

Malicious code in append_only_vec (crates.io)

Malicious code in append_only_vec (crates.io)

Sunlitappend-only-vec · append-only-vecvia OSV
MAL-2026-14332None
1mo ago

Malicious code in aovine (crates.io)

Malicious code in aovine (crates.io)

Sunlitaovine · aovinevia OSV
RUSTSEC-2026-0266None
1mo ago

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

Sunlitinternment · internmentvia OSV
RUSTSEC-2026-0265None
1mo ago

`proc-macro1` was removed from crates.io due to malicious code

`proc-macro1` was removed from crates.io due to malicious code

Sunlitproc-macro1 · proc-macro1via OSV
RUSTSEC-2026-0264None
1mo ago

`proc-macro-en` was removed from crates.io due to malicious code

`proc-macro-en` was removed from crates.io due to malicious code

Sunlitproc-macro-en · proc-macro-envia OSV
RUSTSEC-2026-0263None
1mo ago

`tinymember` was removed from crates.io due to affiliation with malicious code

`tinymember` was removed from crates.io due to affiliation with malicious code

Sunlittinymember · tinymembervia OSV
RUSTSEC-2026-0262None
1mo ago

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

Sunlitappend-only-vec · append-only-vecvia OSV
RUSTSEC-2026-0261None
1mo ago

`aronenao` was removed from crates.io due to malicious code

`aronenao` was removed from crates.io due to malicious code

Sunlitaronenao · aronenaovia OSV
RUSTSEC-2026-0260None
1mo ago

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

Sunlitarrayref · arrayrefvia OSV
RUSTSEC-2026-0259None
1mo ago

`arone` was removed from crates.io due to malicious code

`arone` was removed from crates.io due to malicious code

Sunlitarone · aronevia OSV
CVE-2026-54136Medium
1mo ago

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{worksp…

Sunlitwindmill-api · windmill-apiEPSS 0.35%via NVD
GHSA-qwgh-2vcv-g2f7Medium
1mo ago

block_buffer: panic corrupts inline buffer position

block_buffer: panic corrupts inline buffer position

Sunlitblock_buffer · block_buffervia GHSA
CVE-2026-52834High· 7.3
1mo ago

jxl-oxide is a pure Rust implementation of a JPEG XL decoder

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…

Twilightjxl-grid · jxl-gridEPSS 0.13%via NVD
CVE-2026-75914High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image ext…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.42%via NVD
CVE-2026-75859High· 7.5
1mo ago

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can …

Twilightdeepseek-tui · deepseek-tuiEPSS 0.41%via NVD
CVE-2026-75857High· 7.0
1mo ago

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.19%via NVD
CVE-2026-75913Critical· 9.3
1mo ago

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…

Midnightdeepseek-tui · deepseek-tuiEPSS 0.33%via NVD
CVE-2026-75915High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript c…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.62%via NVD
CVE-2026-75856High· 8.6
1mo ago

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks an…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.46%via NVD
CVE-2026-75912High· 7.4
1mo ago

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.41%via NVD
CVE-2026-75858High· 7.8
1mo ago

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine trea…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.27%via NVD
CVE-2026-75911High· 7.8
1mo ago

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.25%via NVD
RUSTSEC-2026-0271None
1mo ago

FTP command injection via CRLF in control channel arguments

FTP command injection via CRLF in control channel arguments

Sunlitsuppaftp · suppaftpvia OSV
GHSA-vjf8-9fx6-mv6xMedium
1mo ago

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

Sunlittriton-vm · triton-vmvia GHSA
CVE-2026-52736High
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the…

Twilightzebra-state · zebra-stateEPSS 0.44%via NVD
CVE-2026-52735Critical
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcod…

Midnightzebra-script · zebra-scriptEPSS 0.29%via NVD
CVEs tagged “rust” — page 3 · VulnSea