crates.io incidents

Recent crates.io vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

MODERATEcrates.io

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

1 day ago
MODERATEcrates.io

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

1 day ago
HIGHcrates.io

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

1 day ago
MODERATEcrates.io

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

1 day ago
UNKNOWNcrates.io

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)

1 day ago
UNKNOWNcrates.io

`tinymember` was removed from crates.io due to affiliation with malicious code

`tinymember` was removed from crates.io due to affiliation with malicious code

5 days ago
UNKNOWNcrates.io

Malicious code in internment (crates.io)

Malicious code in internment (crates.io)

5 days ago
UNKNOWNcrates.io

Malicious code in tinymember (crates.io)

Malicious code in tinymember (crates.io)

5 days ago
UNKNOWNcrates.io

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency

5 days ago
UNKNOWNcrates.io

Malicious code in arrayref (crates.io)

Malicious code in arrayref (crates.io)

5 days ago
UNKNOWNcrates.io

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency

5 days ago
UNKNOWNcrates.io

Malicious code in append_only_vec (crates.io)

Malicious code in append_only_vec (crates.io)

5 days ago
UNKNOWNcrates.io

`arone` was removed from crates.io due to malicious code

`arone` was removed from crates.io due to malicious code

5 days ago
UNKNOWNcrates.io

Malicious code in proc_macro1 (crates.io)

Malicious code in proc_macro1 (crates.io)

5 days ago
UNKNOWNcrates.io

Malicious code in aronenao (crates.io)

Malicious code in aronenao (crates.io)

5 days ago
UNKNOWNcrates.io

`aronenao` was removed from crates.io due to malicious code

`aronenao` was removed from crates.io due to malicious code

5 days ago
UNKNOWNcrates.io

`proc-macro1` was removed from crates.io due to malicious code

`proc-macro1` was removed from crates.io due to malicious code

5 days ago
UNKNOWNcrates.io

Malicious code in proc_macro_en (crates.io)

Malicious code in proc_macro_en (crates.io)

5 days ago
UNKNOWNcrates.io

`proc-macro-en` was removed from crates.io due to malicious code

`proc-macro-en` was removed from crates.io due to malicious code

5 days ago
UNKNOWNcrates.io

Malicious code in arone (crates.io)

Malicious code in arone (crates.io)

5 days ago
UNKNOWNcrates.io

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

`internment` 0.8.7 was removed from crates.io due to a malicious dependency

5 days ago
UNKNOWNcrates.io

Malicious code in aovine (crates.io)

Malicious code in aovine (crates.io)

5 days ago
MODERATEcrates.io

block_buffer: panic corrupts inline buffer position

block_buffer: panic corrupts inline buffer position

6 days ago
MODERATEcrates.io

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

1 week ago
UNKNOWNcrates.io

h2 unbounded empty DATA frames

h2 unbounded empty DATA frames

1 week ago
MEDIUMcrates.io

s2n-quic has excessive memory allocation

s2n-quic has excessive memory allocation

1 week ago
HIGHcrates.io

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

1 week ago
HIGHcrates.io

nimiq-blockchain: Validity store off by one error

nimiq-blockchain: Validity store off by one error

1 week ago
UNKNOWNcrates.io

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)

2 weeks ago
UNKNOWNcrates.io

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)

2 weeks ago
UNKNOWNcrates.io

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)

2 weeks ago
UNKNOWNcrates.io

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)

2 weeks ago
UNKNOWNcrates.io

Ed25519 identity public keys permit universal signature forgery

Ed25519 identity public keys permit universal signature forgery

2 weeks ago
UNKNOWNcrates.io

Low-level GCM ignores the operation nonce

Low-level GCM ignores the operation nonce

2 weeks ago
UNKNOWNcrates.io

Streaming AEAD does not authenticate stream structure

Streaming AEAD does not authenticate stream structure

2 weeks ago
UNKNOWNcrates.io

Safe ErrorRegistry APIs can cause undefined behavior

Safe ErrorRegistry APIs can cause undefined behavior

2 weeks ago
UNKNOWNcrates.io

`sevenz-rust` is unmaintained

`sevenz-rust` is unmaintained

2 weeks ago
UNKNOWNcrates.io

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.

2 weeks ago
HIGHcrates.io

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

A `BigInt` division panics, and two neighbouring operations answer wrongly in silence

2 weeks ago
UNKNOWNcrates.io

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization

2 weeks ago
UNKNOWNcrates.io

`nostr-relay-builder` is unmaintained

`nostr-relay-builder` is unmaintained

3 weeks ago
HIGHcrates.io

Russh: Channel-scoped server callbacks can be reached without an open channel

Russh: Channel-scoped server callbacks can be reached without an open channel

3 weeks agoEPSS 0%
UNKNOWNcrates.io

`nostr-relay-pool` is unmaintained

`nostr-relay-pool` is unmaintained

3 weeks ago
UNKNOWNcrates.io

`nostr-keyring` is unmaintained

`nostr-keyring` is unmaintained

3 weeks ago
HIGHcrates.io

Processing of unverified relay events

Processing of unverified relay events

3 weeks ago
MEDIUMcrates.io

NIP-04 parsing amplifies malformed ciphertext memory use

NIP-04 parsing amplifies malformed ciphertext memory use

3 weeks ago
HIGHcrates.io

Wallet event parsers accept unauthenticated events

Wallet event parsers accept unauthenticated events

3 weeks ago
HIGHcrates.io

Empty NIP-50 search filters can panic

Empty NIP-50 search filters can panic

3 weeks ago
HIGHcrates.io

Debug output exposes NIP-46 and NIP-60 credentials

Debug output exposes NIP-46 and NIP-60 credentials

3 weeks ago
HIGHcrates.io

Relay authentication challenges can exhaust memory

Relay authentication challenges can exhaust memory

3 weeks ago
HIGHcrates.io

NIP-98 authorization parsing permits resource exhaustion

NIP-98 authorization parsing permits resource exhaustion

3 weeks ago
HIGHcrates.io

NIP-44 v2 decryption permits resource exhaustion

NIP-44 v2 decryption permits resource exhaustion

3 weeks ago
HIGHcrates.io

Verification cache poisoning allows forged Nostr events to bypass signature validation

Verification cache poisoning allows forged Nostr events to bypass signature validation

3 weeks ago
MODERATEcrates.io

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

3 weeks ago
MEDIUMcrates.io

Stores can mix up type indices between engines

Stores can mix up type indices between engines

3 weeks ago
UNKNOWNcrates.io

Preemption and traps during bulk operations enable breaking internal VM state

Preemption and traps during bulk operations enable breaking internal VM state

3 weeks ago
UNKNOWNcrates.io

Unix `BROWSER` handling allows browser argument injection

Unix `BROWSER` handling allows browser argument injection

3 weeks ago
HIGHcrates.io

Remote Denial of Service via malformed NIP-04 IV

Remote Denial of Service via malformed NIP-04 IV

4 weeks ago
HIGHcrates.io

Remote Denial of Service via malformed NIP‑44 v2 payload

Remote Denial of Service via malformed NIP‑44 v2 payload

4 weeks ago
MEDIUMcrates.io

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

4 weeks ago
MEDIUMcrates.io

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

4 weeks ago
MEDIUMcrates.io

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records

4 weeks ago
UNKNOWNcrates.io

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`

1 month ago
UNKNOWNcrates.io

Uint shift operations: incorrect overflow flags and truncated shift amounts

Uint shift operations: incorrect overflow flags and truncated shift amounts

1 month ago
HIGHcrates.io

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

2 months agoEPSS 0%
UNKNOWNcrates.io

Panic on a `DataRow` with fewer fields than columns allows denial of service

Panic on a `DataRow` with fewer fields than columns allows denial of service

2 months ago
UNKNOWNcrates.io

Panic decoding a malformed `hstore` value allows denial of service

Panic decoding a malformed `hstore` value allows denial of service

2 months ago
UNKNOWNcrates.io

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service

2 months ago
UNKNOWNcrates.io

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

2 months ago
UNKNOWNcrates.io

Use-after-free

Use-after-free

3 months ago
UNKNOWNcrates.io

TLS hostname verification disabled when using Boring TLS backend

TLS hostname verification disabled when using Boring TLS backend

3 months agoEPSS 0%
UNKNOWNcrates.io

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc

3 months ago
UNKNOWNcrates.io

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

Potential use-after-free due to lack of panic safety in `LruCache::pop()`

3 months ago
UNKNOWNcrates.io

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables

3 months ago
UNKNOWNcrates.io

Crafted archives can cause a use-after-free during deserialization

Crafted archives can cause a use-after-free during deserialization

3 months ago
HIGHcrates.io

ldap3_proto has LDAP Filter stack exhaustion

ldap3_proto has LDAP Filter stack exhaustion

3 months ago
CRITICALcrates.io

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules

3 months ago
MEDIUMcrates.io

Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability

Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability

3 months agoEPSS 1%
UNKNOWNcrates.io

smartstring is unmaintained

smartstring is unmaintained

3 months ago
UNKNOWNcrates.io

bitmaps is unmaintained

bitmaps is unmaintained

3 months ago
UNKNOWNcrates.io

sized-chunks is unmaintained

sized-chunks is unmaintained

3 months ago
UNKNOWNcrates.io

im-rc is unmaintained

im-rc is unmaintained

3 months ago
UNKNOWNcrates.io

im is unmaintained

im is unmaintained

3 months ago
MODERATEcrates.io

actix-http has HTTP/1.1 CL.TE Request Smuggling

actix-http has HTTP/1.1 CL.TE Request Smuggling

4 months ago
LOWcrates.io

Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`

Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`

6 months ago
UNKNOWNcrates.io

Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext

Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext

6 months ago
MODERATEcrates.io

[actix-files] Panic triggered by empty Range header in GET request for static file

[actix-files] Panic triggered by empty Range header in GET request for static file

6 months ago
MODERATEcrates.io

actix-files has a possible exposure of information vulnerability

actix-files has a possible exposure of information vulnerability

6 months ago
UNKNOWNcrates.io

Unnecessary clamping of seed reduces seed entropy to 251 bits

Unnecessary clamping of seed reduces seed entropy to 251 bits

6 months ago
UNKNOWNcrates.io

X25519 secret validation did not check buffer length or clamping

X25519 secret validation did not check buffer length or clamping

7 months ago
UNKNOWNcrates.io

Incorrect X25519 clamping check rejects all secrets on import

Incorrect X25519 clamping check rejects all secrets on import

7 months ago
HIGHcrates.io

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`

7 months ago
UNKNOWNcrates.io

`Bitmap::try_from(&[u8])` can create invalid values

`Bitmap::try_from(&[u8])` can create invalid values

8 months ago
UNKNOWNcrates.io

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code

1 year ago
UNKNOWNcrates.io

`FormatContext` stream accessors can cause undefined behavior from safe code

`FormatContext` stream accessors can cause undefined behavior from safe code

1 year ago
HIGHcrates.io

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write

1 year ago
UNKNOWNcrates.io

Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write

Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write

1 year ago
MODERATEcrates.io

Some AES functions may panic when overflow checking is enabled in ring

Some AES functions may panic when overflow checking is enabled in ring

1 year ago
HIGHcrates.io

tls-listener affected by the slow loris vulnerability with default configuration

tls-listener affected by the slow loris vulnerability with default configuration

2 years ago
CRITICALcrates.io

Full Table Permissions by Default

Full Table Permissions by Default

2 years ago
UNKNOWNcrates.io

Aliasing violation in `OrdSet` insertion

Aliasing violation in `OrdSet` insertion

3 years ago
UNKNOWNcrates.io

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

5 years ago

Tooling for crates.io

SnykScan your dependencies in CI and fix this vulnerability.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GohexMavenNuGetPackagistPyPIRubyGemsnpm