VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

372 CVEsRSS

CVE-2026-25800High· 7.5
2mo ago

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Twilightquinn-proto · quinn-protoEPSS 0.61%via OSV
GHSA-5xvq-cp9x-6p6rMedium· 5.3
2mo ago

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Sunlitrussh · russhvia GHSA
GHSA-cqjc-rmpq-xprqMedium· 4.3
2mo ago

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Sunlitrussh · russhvia GHSA
GHSA-g9hv-x236-4qp3Medium· 5.3
2mo ago

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Sunlitrussh · russhvia GHSA
GHSA-4w2j-m93h-cj5jHigh· 7.5
2mo ago

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly

Twilightquinn-proto · quinn-protovia GHSA
RUSTSEC-2026-0215None
2mo ago

smallstr is unmaintained

smallstr is unmaintained

Sunlitsmallstr · smallstrvia OSV
RUSTSEC-2026-0214None
2mo ago

gumdrop is unmaintained

gumdrop is unmaintained

Sunlitgumdrop · gumdropvia OSV
RUSTSEC-2026-0218None
2mo ago

`Enum` trait allows type confusion when manually implemented

`Enum` trait allows type confusion when manually implemented

Sunlitenum-map · enum-mapvia OSV
RUSTSEC-2026-0213None
2mo ago

XSS in ammonia via SVG `animate` and `set` animation tags

XSS in ammonia via SVG `animate` and `set` animation tags

Sunlitammonia · ammoniavia OSV
GHSA-ggxf-9f6j-w742Medium
2mo ago

Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`

Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`

Sunlitdiesel · dieselvia GHSA
RUSTSEC-2026-0210None
2mo ago

`libcrux-aesgcm` Renamed to `libcrux-aes`

`libcrux-aesgcm` Renamed to `libcrux-aes`

Sunlitlibcrux-aesgcm · libcrux-aesgcmvia OSV
GHSA-7gcf-g7xr-8hxjMedium
2mo ago

serde_with: KeyValueMap serialization panics on empty sequence or map entries

serde_with: KeyValueMap serialization panics on empty sequence or map entries

Sunlitserde_with · serde_withvia GHSA
RUSTSEC-2026-0211None
2mo ago

Non-constant time Authentication Tag Check in AES-GCM Decryption

Non-constant time Authentication Tag Check in AES-GCM Decryption

Sunlitlibcrux-aesgcm · libcrux-aesgcmvia OSV
RUSTSEC-2026-0221None
2mo ago

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

Sunlitevent-listener · event-listenervia OSV
RUSTSEC-2026-0206None
2mo ago

`rustybuzz` is unmaintained

`rustybuzz` is unmaintained

Sunlitrustybuzz · rustybuzzvia OSV
GHSA-99j7-fhr2-xfj4Critical
2mo ago

`exploration` was removed from crates.io for malicious code

`exploration` was removed from crates.io for malicious code

Midnightexploration · explorationvia GHSA
RUSTSEC-2026-0220None
2mo ago

Uint shift operations: incorrect overflow flags and truncated shift amounts

Uint shift operations: incorrect overflow flags and truncated shift amounts

Sunlitruint · ruintvia OSV
MAL-2026-6959None
2mo ago

Malicious code in proton_pfff (crates.io)

Malicious code in proton_pfff (crates.io)

Sunlitproton-pfff · proton-pfffvia OSV
GHSA-q95x-7g78-rccvMedium
2mo ago

OneRingBuf has a Use After Free Vulnerability

OneRingBuf has a Use After Free Vulnerability

Sunlitoneringbuf · oneringbufvia GHSA
GHSA-cwv4-h3j5-w3cfLow· 3.7
2mo ago

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

Sunlitrama · ramavia GHSA
GHSA-fqf6-gxhh-2xhwHigh
2mo ago

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)

Twilightuucore · uucorevia GHSA
CVE-2026-35341High· 7.1
2mo ago

mkfifo: permissions of an existing file are changed after FIFO creation fails

mkfifo: permissions of an existing file are changed after FIFO creation fails

Twilightuu_mkfifo · uu_mkfifoEPSS 0.17%via GHSA
CVE-2026-35361Low· 3.4
2mo ago

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)

Sunlituu_mknod · uu_mknodEPSS 0.14%via GHSA
CVE-2026-35381Low· 3.3
2mo ago

cut: -s ignored in -z -d '' newline-delimiter mode

cut: -s ignored in -z -d '' newline-delimiter mode

Sunlituu_cut · uu_cutEPSS 0.18%via GHSA
CVE-2026-54496Critical· 9.3
2mo ago

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Midnightzebrad · zebradEPSS 0.32%via GHSA
CVE-2026-35342Low· 3.3
2mo ago

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

Sunlituu_mktemp · uu_mktempEPSS 0.13%via GHSA
CVE-2026-35346Low· 3.3
2mo ago

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

Sunlituu_comm · uu_commEPSS 0.18%via GHSA
CVE-2026-35373Low· 3.3
2mo ago

ln: rejects non-UTF-8 source filenames in target-directory mode

ln: rejects non-UTF-8 source filenames in target-directory mode

Sunlituu_ln · uu_lnEPSS 0.12%via GHSA
CVE-2026-35355Medium· 6.3
2mo ago

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

Sunlituu_install · uu_installEPSS 0.12%via GHSA
CVE-2026-35343Low· 3.3
2mo ago

cut: -s (only-delimited) ignored when delimiter is a newline

cut: -s (only-delimited) ignored when delimiter is a newline

Sunlituu_cut · uu_cutEPSS 0.14%via GHSA
CVEs tagged “rust” — page 6 · VulnSea