VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

372 CVEsRSS

RUSTSEC-2026-0246None
1mo ago

`sevenz-rust` is unmaintained

`sevenz-rust` is unmaintained

Sunlitsevenz-rust · sevenz-rustvia OSV
RUSTSEC-2026-0245None
1mo ago

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

Sunlitsevenz-rust · sevenz-rustvia OSV
RUSTSEC-2026-0244None
1mo ago

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

Sunlitgettext-rs · gettext-rsvia OSV
RUSTSEC-2026-0236High· 7.5
1mo ago

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

Twilightviperjs · viperjsvia OSV
RUSTSEC-2026-0274None
1mo ago

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics

Sunlitrtrb · rtrbvia OSV
RUSTSEC-2026-0243None
1mo ago

`nostr-relay-pool` is unmaintained

`nostr-relay-pool` is unmaintained

Sunlitnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0241None
1mo ago

`nostr-keyring` is unmaintained

`nostr-keyring` is unmaintained

Sunlitnostr-keyring · nostr-keyringvia OSV
RUSTSEC-2026-0237None
1mo ago

`nostr-relay-builder` is unmaintained

`nostr-relay-builder` is unmaintained

Sunlitnostr-relay-builder · nostr-relay-buildervia OSV
CVE-2026-68930Medium· 6.5
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, an…

Sunlitrussh · russhEPSS 0.26%via NVD
RUSTSEC-2026-0232High· 7.5
1mo ago

Processing of unverified relay events

Processing of unverified relay events

Twilightnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0231High· 7.5
1mo ago

Relay authentication challenges can exhaust memory

Relay authentication challenges can exhaust memory

Twilightnostr-relay-pool · nostr-relay-poolvia OSV
RUSTSEC-2026-0230High· 7.5
1mo ago

Empty NIP-50 search filters can panic

Empty NIP-50 search filters can panic

Twilightnostr · nostrvia OSV
RUSTSEC-2026-0229High· 7.5
1mo ago

NIP-98 authorization parsing permits resource exhaustion

NIP-98 authorization parsing permits resource exhaustion

Twilightnostr · nostrvia OSV
RUSTSEC-2026-0228Medium· 4.3
1mo ago

NIP-04 parsing amplifies malformed ciphertext memory use

NIP-04 parsing amplifies malformed ciphertext memory use

Sunlitnostr · nostrvia OSV
RUSTSEC-2026-0227High· 7.5
1mo ago

NIP-44 v2 decryption permits resource exhaustion

NIP-44 v2 decryption permits resource exhaustion

Twilightnostr · nostrvia OSV
RUSTSEC-2026-0226High· 7.5
1mo ago

Wallet event parsers accept unauthenticated events

Wallet event parsers accept unauthenticated events

Twilightnostr · nostrvia OSV
RUSTSEC-2026-0225Medium· 5.5
1mo ago

Debug output exposes NIP-46 and NIP-60 credentials

Debug output exposes NIP-46 and NIP-60 credentials

Sunlitnostr · nostrvia OSV
RUSTSEC-2026-0224High· 7.5
1mo ago

Verification cache poisoning allows forged Nostr events to bypass signature validation

Verification cache poisoning allows forged Nostr events to bypass signature validation

Twilightnostr-relay-pool · nostr-relay-poolvia OSV
GHSA-3whf-vgf2-9w6gMedium
1mo ago

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

Sunlitzaino-state · zaino-statevia GHSA
RUSTSEC-2026-0223None
1mo ago

Preemption and traps during bulk operations enable breaking internal VM state

Preemption and traps during bulk operations enable breaking internal VM state

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0222Low· 3.8
1mo ago

Stores can mix up type indices between engines

Stores can mix up type indices between engines

Sunlitwasmtime · wasmtimevia OSV
RUSTSEC-2026-0257None
1mo ago

Unix `BROWSER` handling allows browser argument injection

Unix `BROWSER` handling allows browser argument injection

Sunlitwebbrowser · webbrowservia OSV
GHSA-6xx4-9wp6-65p7Medium· 6.5
1mo ago

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

Sunlitskilo · skilovia GHSA
GHSA-hc4m-q9jh-xw4jMedium· 6.6
1mo ago

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

nono-cli'scregistry pack verification can fail open when provenance metadata is absent

Sunlitnono-cli · nono-clivia GHSA
RUSTSEC-2026-0219High· 7.5
1mo ago

Remote Denial of Service via malformed NIP-04 IV

Remote Denial of Service via malformed NIP-04 IV

Twilightnostr · nostrvia OSV
RUSTSEC-2026-0216High· 7.5
2mo ago

Remote Denial of Service via malformed NIP‑44 v2 payload

Remote Denial of Service via malformed NIP‑44 v2 payload

Twilightnostr · nostrvia OSV
GHSA-f45q-w629-wr25Medium
2mo ago

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects

Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-qqc3-94qv-7fw3Medium
2mo ago

Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic

Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic

Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-2625-rw7m-5q5xLow
2mo ago

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

Sunlithubuum_client · hubuum_clientvia GHSA
CVE-2026-16756High· 7.5
2mo ago

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Twilightaws-smithy-http-server · aws-smithy-http-serverEPSS 0.75%via GHSA
CVEs tagged “rust” — page 5 · VulnSea