VulnSea

Tagged “rust”

CVEs tagged rust, newest first.

383 CVEsRSS

CVE-2026-5222Low
3mo ago

Cargo can be coerced to share credentials between registries

Cargo can be coerced to share credentials between registries

Sunlitcargo · cargoEPSS 0.48%via GHSA
CVE-2026-5223Medium
3mo ago

Cargo crates in third party registries can override the cached source of other crates

Cargo crates in third party registries can override the cached source of other crates

Sunlitcargo · cargoEPSS 0.29%via GHSA
GHSA-fq3w-p4fg-mw73Low
3mo ago

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

fixurjavainstall: Previous Fuji versions can accidentally wipe `/usr/share/man/man8`

Sunlitfixurjavainstall · fixurjavainstallvia GHSA
CVE-2026-48504Medium· 5.3
3mo ago

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation

Sunlitopentelemetry_sdk · opentelemetry_sdkEPSS 0.42%via GHSA
CVE-2026-58494Medium· 6.5
3mo ago

WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination

WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination

Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.17%via OSV
CVE-2026-54557Medium· 5.5
3mo ago

mise HTTP backend uses raw version path for install symlink destination

mise HTTP backend uses raw version path for install symlink destination

Sunlitmise · miseEPSS 0.17%via GHSA
CVE-2026-55441High· 8.6
3mo ago

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Twilightmise · miseEPSS 0.18%via GHSA
CVE-2026-55448Medium· 6.3
3mo ago

Mise's local credential_command executes untrusted config

Mise's local credential_command executes untrusted config

Sunlitmise · miseEPSS 0.16%via GHSA
CVE-2026-33646Critical· 9.6
3mo ago

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)

Midnightmise · miseEPSS 0.69%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

Twilightskillctl · skillctlvia GHSA
CVE-2026-63738Medium· 4.3
3mo ago

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

Sunlitsurrealdb · surrealdbEPSS 0.28%via OSV
CVE-2026-11941Medium· 5.6
3mo ago

Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions

Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions

Sunlitquiche · quicheEPSS 0.25%via GHSA
GHSA-h5rg-8p7f-47g2Medium· 4.1
3mo ago

SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch

Sunlitsurrealdb · surrealdbvia GHSA
GHSA-cc8f-fcx3-gpjrHigh· 7.7
3mo ago

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

Twilightsurrealdb · surrealdbvia GHSA
GHSA-h4h3-3rfj-x6fqMedium· 4.3
3mo ago

SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field

Sunlitsurrealdb · surrealdbvia GHSA
GHSA-hv6h-hc26-q48pMedium· 4.3
3mo ago

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals

Sunlitsurrealdb · surrealdbvia GHSA
GHSA-jv2j-mqmw-xvv5Medium· 6.5
3mo ago

SurrealDB: Denial of Service via deep operator chains

SurrealDB: Denial of Service via deep operator chains

Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49859Medium· 5.2
3mo ago

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

Sunlitdeno · denoEPSS 0.14%via GHSA
CVE-2026-49860Medium· 5.2
3mo ago

Deno: WebSocket API sandbox bypass via missing post-DNS check

Deno: WebSocket API sandbox bypass via missing post-DNS check

Sunlitdeno · denoEPSS 0.14%via GHSA
CVE-2026-49402High· 8.1
3mo ago

Deno: Command Injection via spawnSync & spawn on Windows

Deno: Command Injection via spawnSync & spawn on Windows

Twilightdeno · denoEPSS 0.45%via GHSA
CVE-2026-49440High· 7.4
3mo ago

Deno: Miller-Rabin Primality Test Allows Zero Rounds

Deno: Miller-Rabin Primality Test Allows Zero Rounds

Twilightdeno · denoEPSS 0.24%via GHSA
CVE-2026-49411Medium· 6.5
3mo ago

Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks

Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks

Sunlitdeno · denoEPSS 0.16%via GHSA
CVE-2026-49406Medium· 5.5
3mo ago

Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

Sunlitdeno · denoEPSS 0.18%via GHSA
CVE-2026-49401Medium· 5.2
3mo ago

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Sunlitdeno · denoEPSS 0.20%via GHSA
CVE-2026-54786None
3mo ago

Leak in WASIp1 `fd_renumber` implementation

Leak in WASIp1 `fd_renumber` implementation

Sunlitwasmtime-wasi · wasmtime-wasiEPSS 0.22%via OSV
RUSTSEC-2026-0180None
3mo ago

Panic decoding a malformed `hstore` value allows denial of service

Panic decoding a malformed `hstore` value allows denial of service

Sunlitpostgres-protocol · postgres-protocolvia OSV
RUSTSEC-2026-0179None
3mo ago

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

Sunlitpostgres-protocol · postgres-protocolvia OSV
RUSTSEC-2026-0178None
3mo ago

Panic on a `DataRow` with fewer fields than columns allows denial of service

Panic on a `DataRow` with fewer fields than columns allows denial of service

Sunlittokio-postgres · tokio-postgresvia OSV
GHSA-36hh-v3qg-5jq4High
3mo ago

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators

Twilightpyo3 · pyo3via GHSA
GHSA-chgr-c6px-7xppMedium
3mo ago

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

Sunlitpyo3 · pyo3via GHSA
CVEs tagged “rust” — page 9 · VulnSea