Tagged “rust”
CVEs tagged rust, newest first.
372 CVEsRSS
MAL-2026-14337NoneMalicious code in internment (crates.io)
Malicious code in internment (crates.io)
MAL-2026-14336NoneMalicious code in arrayref (crates.io)
Malicious code in arrayref (crates.io)
MAL-2026-14335NoneMalicious code in aronenao (crates.io)
Malicious code in aronenao (crates.io)
MAL-2026-14334NoneMalicious code in arone (crates.io)
Malicious code in arone (crates.io)
MAL-2026-14333NoneMalicious code in append_only_vec (crates.io)
Malicious code in append_only_vec (crates.io)
MAL-2026-14332NoneMalicious code in aovine (crates.io)
Malicious code in aovine (crates.io)
RUSTSEC-2026-0266None`internment` 0.8.7 was removed from crates.io due to a malicious dependency
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
RUSTSEC-2026-0265None`proc-macro1` was removed from crates.io due to malicious code
`proc-macro1` was removed from crates.io due to malicious code
RUSTSEC-2026-0264None`proc-macro-en` was removed from crates.io due to malicious code
`proc-macro-en` was removed from crates.io due to malicious code
RUSTSEC-2026-0263None`tinymember` was removed from crates.io due to affiliation with malicious code
`tinymember` was removed from crates.io due to affiliation with malicious code
RUSTSEC-2026-0262None`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
RUSTSEC-2026-0261None`aronenao` was removed from crates.io due to malicious code
`aronenao` was removed from crates.io due to malicious code
RUSTSEC-2026-0260None`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
RUSTSEC-2026-0259None`arone` was removed from crates.io due to malicious code
`arone` was removed from crates.io due to malicious code
CVE-2026-54136MediumWindmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{worksp…
GHSA-qwgh-2vcv-g2f7Mediumblock_buffer: panic corrupts inline buffer position
block_buffer: panic corrupts inline buffer position
CVE-2026-52834High· 7.3jxl-oxide is a pure Rust implementation of a JPEG XL decoder
jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…
CVE-2026-75914High· 7.5CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image ext…
CVE-2026-75859High· 7.5CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can …
CVE-2026-75857High· 7.0CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-…
CVE-2026-75913Critical· 9.3CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool
CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…
CVE-2026-75915High· 7.5CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript c…
CVE-2026-75856High· 8.6CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks an…
CVE-2026-75912High· 7.4CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values…
CVE-2026-75858High· 7.8CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine trea…
CVE-2026-75911High· 7.8CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…
RUSTSEC-2026-0271NoneFTP command injection via CRLF in control channel arguments
FTP command injection via CRLF in control channel arguments
GHSA-vjf8-9fx6-mv6xMediumTriton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
CVE-2026-52736HighZEBRA is a Zcash node written entirely in Rust
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the…
CVE-2026-52735CriticalZEBRA is a Zcash node written entirely in Rust
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcod…