crates.io incidents
Recent crates.io vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
Russh: Channel-scoped server callbacks can be reached without an open channel
Russh: Channel-scoped server callbacks can be reached without an open channel
Verification cache poisoning allows forged Nostr events to bypass signature validation
Verification cache poisoning allows forged Nostr events to bypass signature validation
Processing of unverified relay events
Processing of unverified relay events
NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
Relay authentication challenges can exhaust memory
Relay authentication challenges can exhaust memory
Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
Stores can mix up type indices between engines
Stores can mix up type indices between engines
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Preemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
Uint shift operations: incorrect overflow flags and truncated shift amounts
Uint shift operations: incorrect overflow flags and truncated shift amounts
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Use-after-free
Use-after-free
TLS hostname verification disabled when using Boring TLS backend
TLS hostname verification disabled when using Boring TLS backend
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Crafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Tooling for crates.io
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.