Tagged “rust”
CVEs tagged rust, newest first.
372 CVEsRSS
RUSTSEC-2026-0246None`sevenz-rust` is unmaintained
`sevenz-rust` is unmaintained
RUSTSEC-2026-0245NoneRelative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
RUSTSEC-2026-0244None`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
RUSTSEC-2026-0236High· 7.5A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
RUSTSEC-2026-0274NoneDouble free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
RUSTSEC-2026-0243None`nostr-relay-pool` is unmaintained
`nostr-relay-pool` is unmaintained
RUSTSEC-2026-0241None`nostr-keyring` is unmaintained
`nostr-keyring` is unmaintained
RUSTSEC-2026-0237None`nostr-relay-builder` is unmaintained
`nostr-relay-builder` is unmaintained
CVE-2026-68930Medium· 6.5Russh is a Rust SSH client & server library
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, an…
RUSTSEC-2026-0232High· 7.5Processing of unverified relay events
Processing of unverified relay events
RUSTSEC-2026-0231High· 7.5Relay authentication challenges can exhaust memory
Relay authentication challenges can exhaust memory
RUSTSEC-2026-0230High· 7.5Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
RUSTSEC-2026-0229High· 7.5NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
RUSTSEC-2026-0228Medium· 4.3NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
RUSTSEC-2026-0227High· 7.5NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
RUSTSEC-2026-0226High· 7.5Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
RUSTSEC-2026-0225Medium· 5.5Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
RUSTSEC-2026-0224High· 7.5Verification cache poisoning allows forged Nostr events to bypass signature validation
Verification cache poisoning allows forged Nostr events to bypass signature validation
GHSA-3whf-vgf2-9w6gMediumzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
RUSTSEC-2026-0223NonePreemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
RUSTSEC-2026-0222Low· 3.8Stores can mix up type indices between engines
Stores can mix up type indices between engines
RUSTSEC-2026-0257NoneUnix `BROWSER` handling allows browser argument injection
Unix `BROWSER` handling allows browser argument injection
GHSA-6xx4-9wp6-65p7Medium· 6.5skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
GHSA-hc4m-q9jh-xw4jMedium· 6.6nono-cli'scregistry pack verification can fail open when provenance metadata is absent
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
RUSTSEC-2026-0219High· 7.5Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
RUSTSEC-2026-0216High· 7.5Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
GHSA-f45q-w629-wr25MediumHubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-qqc3-94qv-7fw3MediumHubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-2625-rw7m-5q5xLowHubuum client library (Rust): Sensitive data may be exposed through default diagnostics
Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics
CVE-2026-16756High· 7.5Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service