Tagged “rust”
CVEs tagged rust, newest first.
383 CVEsRSS
CVE-2026-5222LowCargo can be coerced to share credentials between registries
Cargo can be coerced to share credentials between registries
CVE-2026-5223MediumCargo crates in third party registries can override the cached source of other crates
Cargo crates in third party registries can override the cached source of other crates
GHSA-fq3w-p4fg-mw73Lowfixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`
CVE-2026-48504Medium· 5.3opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
CVE-2026-58494Medium· 6.5WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
CVE-2026-54557Medium· 5.5mise HTTP backend uses raw version path for install symlink destination
mise HTTP backend uses raw version path for install symlink destination
CVE-2026-55441High· 8.6Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
CVE-2026-55448Medium· 6.3Mise's local credential_command executes untrusted config
Mise's local credential_command executes untrusted config
CVE-2026-33646Critical· 9.6Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
GHSA-74p7-6h78-gw8pHighskillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
CVE-2026-63738Medium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
CVE-2026-11941Medium· 5.6Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
GHSA-h5rg-8p7f-47g2Medium· 4.1SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
GHSA-h4h3-3rfj-x6fqMedium· 4.3SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
GHSA-hv6h-hc26-q48pMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
GHSA-jv2j-mqmw-xvv5Medium· 6.5SurrealDB: Denial of Service via deep operator chains
SurrealDB: Denial of Service via deep operator chains
CVE-2026-49859Medium· 5.2Deno: `fetch()` API sandbox bypass via missing DNS resolution check
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVE-2026-49860Medium· 5.2Deno: WebSocket API sandbox bypass via missing post-DNS check
Deno: WebSocket API sandbox bypass via missing post-DNS check
CVE-2026-49402High· 8.1Deno: Command Injection via spawnSync & spawn on Windows
Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-49440High· 7.4Deno: Miller-Rabin Primality Test Allows Zero Rounds
Deno: Miller-Rabin Primality Test Allows Zero Rounds
CVE-2026-49411Medium· 6.5Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
CVE-2026-49406Medium· 5.5Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
CVE-2026-49401Medium· 5.2Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
CVE-2026-54786NoneLeak in WASIp1 `fd_renumber` implementation
Leak in WASIp1 `fd_renumber` implementation
RUSTSEC-2026-0180NonePanic decoding a malformed `hstore` value allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
RUSTSEC-2026-0179NoneUnbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
RUSTSEC-2026-0178NonePanic on a `DataRow` with fewer fields than columns allows denial of service
Panic on a `DataRow` with fewer fields than columns allows denial of service
GHSA-36hh-v3qg-5jq4HighPyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
GHSA-chgr-c6px-7xppMediumPyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures