Tagged “rust”
CVEs tagged rust, newest first.
372 CVEsRSS
CVE-2026-25800High· 7.5Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-5xvq-cp9x-6p6rMedium· 5.3Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-cqjc-rmpq-xprqMedium· 4.3Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-g9hv-x236-4qp3Medium· 5.3Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-4w2j-m93h-cj5jHigh· 7.5Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
RUSTSEC-2026-0215Nonesmallstr is unmaintained
smallstr is unmaintained
RUSTSEC-2026-0214Nonegumdrop is unmaintained
gumdrop is unmaintained
RUSTSEC-2026-0218None`Enum` trait allows type confusion when manually implemented
`Enum` trait allows type confusion when manually implemented
RUSTSEC-2026-0213NoneXSS in ammonia via SVG `animate` and `set` animation tags
XSS in ammonia via SVG `animate` and `set` animation tags
GHSA-ggxf-9f6j-w742MediumDiesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
Diesel has possible use after free when deserializing a SQLite database via `SqliteConnection::deserialize_readonly_database`
RUSTSEC-2026-0210None`libcrux-aesgcm` Renamed to `libcrux-aes`
`libcrux-aesgcm` Renamed to `libcrux-aes`
GHSA-7gcf-g7xr-8hxjMediumserde_with: KeyValueMap serialization panics on empty sequence or map entries
serde_with: KeyValueMap serialization panics on empty sequence or map entries
RUSTSEC-2026-0211NoneNon-constant time Authentication Tag Check in AES-GCM Decryption
Non-constant time Authentication Tag Check in AES-GCM Decryption
RUSTSEC-2026-0221None`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
RUSTSEC-2026-0206None`rustybuzz` is unmaintained
`rustybuzz` is unmaintained
GHSA-99j7-fhr2-xfj4Critical`exploration` was removed from crates.io for malicious code
`exploration` was removed from crates.io for malicious code
RUSTSEC-2026-0220NoneUint shift operations: incorrect overflow flags and truncated shift amounts
Uint shift operations: incorrect overflow flags and truncated shift amounts
MAL-2026-6959NoneMalicious code in proton_pfff (crates.io)
Malicious code in proton_pfff (crates.io)
GHSA-q95x-7g78-rccvMediumOneRingBuf has a Use After Free Vulnerability
OneRingBuf has a Use After Free Vulnerability
GHSA-cwv4-h3j5-w3cfLow· 3.7rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
GHSA-fqf6-gxhh-2xhwHighuutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
CVE-2026-35341High· 7.1mkfifo: permissions of an existing file are changed after FIFO creation fails
mkfifo: permissions of an existing file are changed after FIFO creation fails
CVE-2026-35361Low· 3.4mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node)
CVE-2026-35381Low· 3.3cut: -s ignored in -z -d '' newline-delimiter mode
cut: -s ignored in -z -d '' newline-delimiter mode
CVE-2026-54496Critical· 9.3Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
CVE-2026-35342Low· 3.3mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
CVE-2026-35346Low· 3.3comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output
CVE-2026-35373Low· 3.3ln: rejects non-UTF-8 source filenames in target-directory mode
ln: rejects non-UTF-8 source filenames in target-directory mode
CVE-2026-35355Medium· 6.3install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
CVE-2026-35343Low· 3.3cut: -s (only-delimited) ignored when delimiter is a newline
cut: -s (only-delimited) ignored when delimiter is a newline