crates.io incidents
Recent crates.io vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
anymap2 is unmaintained
anymap2 is unmaintained
rmcp OAuth client fetches server-controlled resource_metadata URLs
rmcp OAuth client fetches server-controlled resource_metadata URLs
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow
Wasmtime wasi:http implementation panics with a zero timeout supplied
Wasmtime wasi:http implementation panics with a zero timeout supplied
Excessive allocated memory on the host when guests don't have stdio
Excessive allocated memory on the host when guests don't have stdio
Guest can panic host through filesystem timestamp before the epoch on wasip3
Guest can panic host through filesystem timestamp before the epoch on wasip3
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Praxis affected by HTTP/2 Bomb
Praxis affected by HTTP/2 Bomb
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release
fd_readdir copies uninitialized struct padding into guest memory
fd_readdir copies uninitialized struct padding into guest memory
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption
Mis-typed WebAssembly tag imports can lead to GC heap corruption
Mis-typed WebAssembly tag imports can lead to GC heap corruption
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic
A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process
A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process
Sending custom to-device messages may panics
Sending custom to-device messages may panics
Use-after-free when XML includes have duplicated entities
Use-after-free when XML includes have duplicated entities
`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)
`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
pqc_kyber is unmaintained
pqc_kyber is unmaintained
RMCP: Custom HTTP headers leak to cross-origin redirect targets
RMCP: Custom HTTP headers leak to cross-origin redirect targets
cosmian_kyber is unmaintained
cosmian_kyber is unmaintained
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
Out-of-bounds read when decoding CKA_ALLOWED_MECHANISMS
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
clear_on_drop is unmaintained
clear_on_drop is unmaintained
Malicious code in logs_update (crates.io)
Malicious code in logs_update (crates.io)
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
gix-sec safe.directory protections absent for elevated administrators
gix-sec safe.directory protections absent for elevated administrators
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
Double free in `AlignedBox<[T]>::realloc_with_default` when an element's `Drop` panics
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup` 1.3.1-dev.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
`greentic-setup-dev` 1.3.34027618345 was removed from crates.io due to containing malicious code
SurrealDB allows bypass of deny-net flags via DNS resolution
SurrealDB allows bypass of deny-net flags via DNS resolution
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
Hurl: Cookies in Cookies section leak when redirecting to a different host
Hurl: Cookies in Cookies section leak when redirecting to a different host
`zbus_polkit`: authorization bypass via PID reuse
`zbus_polkit`: authorization bypass via PID reuse
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Wasmtime has a leak in WASIp1 `fd_renumber` implementation
Path traversal in apimock's file-serving fallback
Path traversal in apimock's file-serving fallback
Path traversal in apimock-server's file-serving fallback
Path traversal in apimock-server's file-serving fallback
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
Malicious code in arone (crates.io)
Malicious code in arone (crates.io)
`proc-macro-en` was removed from crates.io due to malicious code
`proc-macro-en` was removed from crates.io due to malicious code
Malicious code in proc_macro_en (crates.io)
Malicious code in proc_macro_en (crates.io)
`proc-macro1` was removed from crates.io due to malicious code
`proc-macro1` was removed from crates.io due to malicious code
`aronenao` was removed from crates.io due to malicious code
`aronenao` was removed from crates.io due to malicious code
`arone` was removed from crates.io due to malicious code
`arone` was removed from crates.io due to malicious code
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
Malicious code in arrayref (crates.io)
Malicious code in arrayref (crates.io)
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
Malicious code in proc_macro1 (crates.io)
Malicious code in proc_macro1 (crates.io)
Malicious code in tinymember (crates.io)
Malicious code in tinymember (crates.io)
Malicious code in internment (crates.io)
Malicious code in internment (crates.io)
`tinymember` was removed from crates.io due to affiliation with malicious code
`tinymember` was removed from crates.io due to affiliation with malicious code
Malicious code in aovine (crates.io)
Malicious code in aovine (crates.io)
Malicious code in append_only_vec (crates.io)
Malicious code in append_only_vec (crates.io)
Malicious code in aronenao (crates.io)
Malicious code in aronenao (crates.io)
block_buffer: panic corrupts inline buffer position
block_buffer: panic corrupts inline buffer position
Triton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
h2 unbounded empty DATA frames
h2 unbounded empty DATA frames
cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery
cosmian_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery
pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery
pqc_kyber: AVX2 backend skips Fujisaki-Okamoto implicit rejection, enabling chosen-ciphertext key recovery
Legacy `azure_core` writes the `authorization` header value to logs
Legacy `azure_core` writes the `authorization` header value to logs
s2n-quic has excessive memory allocation
s2n-quic has excessive memory allocation
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
nimiq-blockchain: Validity store off by one error
nimiq-blockchain: Validity store off by one error
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
Low-level GCM ignores the operation nonce
Low-level GCM ignores the operation nonce
Streaming AEAD does not authenticate stream structure
Streaming AEAD does not authenticate stream structure
Safe ErrorRegistry APIs can cause undefined behavior
Safe ErrorRegistry APIs can cause undefined behavior
Ed25519 identity public keys permit universal signature forgery
Ed25519 identity public keys permit universal signature forgery
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
`sevenz-rust` is unmaintained
`sevenz-rust` is unmaintained
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
Double free / use-after-free in `ReadChunk::commit` when an element's `Drop` panics
Russh: Channel-scoped server callbacks can be reached without an open channel
Russh: Channel-scoped server callbacks can be reached without an open channel
`nostr-relay-pool` is unmaintained
`nostr-relay-pool` is unmaintained
`nostr-keyring` is unmaintained
`nostr-keyring` is unmaintained
`nostr-relay-builder` is unmaintained
`nostr-relay-builder` is unmaintained
Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
Processing of unverified relay events
Processing of unverified relay events
Verification cache poisoning allows forged Nostr events to bypass signature validation
Verification cache poisoning allows forged Nostr events to bypass signature validation
Relay authentication challenges can exhaust memory
Relay authentication challenges can exhaust memory
NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
Stores can mix up type indices between engines
Stores can mix up type indices between engines
Preemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Unix `BROWSER` handling allows browser argument injection
Unix `BROWSER` handling allows browser argument injection
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
XSS in ammonia via SVG `animate` and `set` animation tags
XSS in ammonia via SVG `animate` and `set` animation tags
serde_with: KeyValueMap serialization panics on empty sequence or map entries
serde_with: KeyValueMap serialization panics on empty sequence or map entries
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
Uint shift operations: incorrect overflow flags and truncated shift amounts
Uint shift operations: incorrect overflow flags and truncated shift amounts
async-tar PAX extension-header desync enables tar entry/content smuggling
async-tar PAX extension-header desync enables tar entry/content smuggling
Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
Unbounded page slicing from attacker-controlled CSS height causes denial of service
Unbounded page slicing from attacker-controlled CSS height causes denial of service
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set
Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB: Authenticated callers can read fields hidden by field-level SELECT permissions via error messages
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: ES512 silently downgraded to ES384 due to jsonwebtoken crate limitation
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Scraping a TABLE with no available PERMISSIONS to current auth level
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries
SurrealDB has Denial of Service in JSON parser due to nested objects
SurrealDB has Denial of Service in JSON parser due to nested objects
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Leak in WASIp1 `fd_renumber` implementation
Leak in WASIp1 `fd_renumber` implementation
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
Panic on a `DataRow` with fewer fields than columns allows denial of service
Panic on a `DataRow` with fewer fields than columns allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
russh server userauth state is not reset when authentication principal changes
russh server userauth state is not reset when authentication principal changes
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets
tar has a PAX header desynchronization issue
tar has a PAX header desynchronization issue
Use-after-free
Use-after-free
Russh: Unchecked CryptoVec allocation and growth handling is reachable
Russh: Unchecked CryptoVec allocation and growth handling is reachable
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
TLS hostname verification disabled when using Boring TLS backend
TLS hostname verification disabled when using Boring TLS backend
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
Crafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
wasmtime has a panic when allocating a table exceeding the size of the host's address space
wasmtime has a panic when allocating a table exceeding the size of the host's address space
imageproc: integer overflow in kernel size check leads to out-of-bounds read
imageproc: integer overflow in kernel size check leads to out-of-bounds read
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
ldap3_proto has LDAP Filter stack exhaustion
ldap3_proto has LDAP Filter stack exhaustion
astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks
astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
rpassword affected by partial password reveal when input is interrupted
rpassword affected by partial password reveal when input is interrupted
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
awslabs/tough Delegated Roles have a Signature Threshold Bypass
awslabs/tough Delegated Roles have a Signature Threshold Bypass
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
awslabs/tough is Missing Delegated Metadata Validation
awslabs/tough is Missing Delegated Metadata Validation
gix-transport: HTTP credentials leaked to redirected host in curl backend
gix-transport: HTTP credentials leaked to redirected host in curl backend
bitmaps is unmaintained
bitmaps is unmaintained
im is unmaintained
im is unmaintained
im-rc is unmaintained
im-rc is unmaintained
smartstring is unmaintained
smartstring is unmaintained
sized-chunks is unmaintained
sized-chunks is unmaintained
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails
uutils coreutils doesn't properly handle setuid and setgid bits when ownership preservation fails
uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths
uutils coreutils has an Uncaught Exception When Encountering Valid but Non-UTF-8 Paths
uutils coreutils has a Link Following issue
uutils coreutils has a Link Following issue
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries
uutils coreutils doesn't preserve file ownership during moves across different filesystem boundaries
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
Reachable panic in certificate revocation list parsing
Reachable panic in certificate revocation list parsing
actix-http has HTTP/1.1 CL.TE Request Smuggling
actix-http has HTTP/1.1 CL.TE Request Smuggling
uutils coreutils has a Link Following Issue
uutils coreutils has a Link Following Issue
uutils coreutils has an Unchecked Return Value Issue
uutils coreutils has an Unchecked Return Value Issue
uutils coreutils has an Incorrect Permission Assignment for Critical Resource
uutils coreutils has an Incorrect Permission Assignment for Critical Resource
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
uutils coreutils has a Time-of-Check to Time-of-Use (TOCTOU) race condition
rust-openssl has incorrect bounds assertion in aes key wrap
rust-openssl has incorrect bounds assertion in aes key wrap
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has an Improper Input Validation Issue in its env Utility
uutils coreutils has an Improper Input Validation Issue in its env Utility
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
uutils coreutils has an Untrusted Search Path
uutils coreutils has an Untrusted Search Path
webpki: Name constraints for URI names were incorrectly accepted
webpki: Name constraints for URI names were incorrectly accepted
webpki: Name constraints were accepted for certificates asserting a wildcard name
webpki: Name constraints were accepted for certificates asserting a wildcard name
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
Name constraints for URI names were incorrectly accepted
Name constraints for URI names were incorrectly accepted
Name constraints were accepted for certificates asserting a wildcard name
Name constraints were accepted for certificates asserting a wildcard name
Rand is unsound with a custom logger using rand::rng()
Rand is unsound with a custom logger using rand::rng()
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
Wasmtime has use-after-free bug after cloning `wasmtime::Linker`
Wasmtime has use-after-free bug after cloning `wasmtime::Linker`
Wasmtime has data leakage between pooling allocator instances
Wasmtime has data leakage between pooling allocator instances
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
Wasmtime has host panic when Winch compiler executes `table.fill`
Wasmtime has host panic when Winch compiler executes `table.fill`
Wasmtime has a possible panic when lifting `flags` component value
Wasmtime has a possible panic when lifting `flags` component value
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
Wasmtime has host data leakage with 64-bit tables and Winch
Wasmtime has host data leakage with 64-bit tables and Winch
Wasmtime: Panic when transcoding misaligned utf-16 strings
Wasmtime: Panic when transcoding misaligned utf-16 strings
Wasmtime has out-of-bounds write or crash when transcoding component model strings
Wasmtime has out-of-bounds write or crash when transcoding component model strings
Stubbed cryptography without warnings
Stubbed cryptography without warnings
libcrux-sha3: Incorrect output from SHAKE squeeze functions
libcrux-sha3: Incorrect output from SHAKE squeeze functions
CRL Distribution Point Scope Check Logic Error in AWS-LC
CRL Distribution Point Scope Check Logic Error in AWS-LC
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN
tar-rs incorrectly ignores PAX size headers if header size is nonzero
tar-rs incorrectly ignores PAX size headers if header size is nonzero
tar-rs `unpack_in` can chmod arbitrary directories by following symlinks
tar-rs `unpack_in` can chmod arbitrary directories by following symlinks
CRLs not considered authoritative by Distribution Point due to faulty matching logic
CRLs not considered authoritative by Distribution Point due to faulty matching logic
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
webpki: CRLs not considered authoritative by Distribution Point due to faulty matching logic
astral-tokio-tar insufficiently validates PAX extensions during extraction
astral-tokio-tar insufficiently validates PAX extensions during extraction
lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
lz4_flex's decompression can leak information from uninitialized memory or reused output buffer
actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects
actix-web-lab has host header poisoning in redirect middleware can generate attacker-controlled absolute redirects
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
AWS-LC has Timing Side-Channel in AES-CCM Tag Verification
AWS-LC has PKCS7_verify Signature Validation Bypass
AWS-LC has PKCS7_verify Signature Validation Bypass
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Unsoundness in opt-in ARMv8 assembly backend for `keccak`
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext
Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext
actix-files has a possible exposure of information vulnerability
actix-files has a possible exposure of information vulnerability
[actix-files] Panic triggered by empty Range header in GET request for static file
[actix-files] Panic triggered by empty Range header in GET request for static file
time vulnerable to stack exhaustion Denial of Service attack
time vulnerable to stack exhaustion Denial of Service attack
Unnecessary clamping of seed reduces seed entropy to 251 bits
Unnecessary clamping of seed reduces seed entropy to 251 bits
git2 has potential undefined behavior when dereferencing Buf struct
git2 has potential undefined behavior when dereferencing Buf struct
bytes has integer overflow in BytesMut::reserve
bytes has integer overflow in BytesMut::reserve
jsonwebtoken has Type Confusion that leads to potential authorization bypass
jsonwebtoken has Type Confusion that leads to potential authorization bypass
oneshot has potential Use After Free when used asynchronously
oneshot has potential Use After Free when used asynchronously
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64
X25519 secret validation did not check buffer length or clamping
X25519 secret validation did not check buffer length or clamping
Incorrect X25519 clamping check rejects all secrets on import
Incorrect X25519 clamping check rejects all secrets on import
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
`IterMut` violates Stacked Borrows by invalidating internal pointer
`IterMut` violates Stacked Borrows by invalidating internal pointer
rsa crate has potential panic on a prime being equal to 1
rsa crate has potential panic on a prime being equal to 1
gix-date can create non-utf8 string with `TimeBuf::as_str`
gix-date can create non-utf8 string with `TimeBuf::as_str`
`Bitmap::try_from(&[u8])` can create invalid values
`Bitmap::try_from(&[u8])` can create invalid values
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short
Critical Use-After-Free in Wasmi's Linear Memory
Critical Use-After-Free in Wasmi's Linear Memory
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Wasmtime provides unsound API access to a WebAssembly shared linear memory
astral-tokio-tar Vulnerable to PAX Header Desynchronization
astral-tokio-tar Vulnerable to PAX Header Desynchronization
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
risc0 vulnerable to arbitrary code execution in guest via memory safety failure in `sys_read`
risc0-aggregation: before 0.9
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Tracing logging user input may result in poisoning logs with ANSI escape sequences
Tracing logging user input may result in poisoning logs with ANSI escape sequences
webp crate may expose memory contents when encoding an image
webp crate may expose memory contents when encoding an image
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
slab allows out-of-bounds access in `get_disjoint_mut` due to incorrect bounds check
quiche connection ID retirement can trigger an infinite loop
quiche connection ID retirement can trigger an infinite loop
russh is missing overflow checks during channel windows adjust
russh is missing overflow checks during channel windows adjust
Wasmtime CLI is vulnerable to host panic through its fd_renumber function
Wasmtime CLI is vulnerable to host panic through its fd_renumber function
users may append `root` to group listings
users may append `root` to group listings
Deno's AES GCM authentication tags are not verified
Deno's AES GCM authentication tags are not verified
Deno run with --allow-read and --deny-read flags results in allowed
Deno run with --allow-read and --deny-read flags results in allowed
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
sudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
`FormatContext` stream accessors can cause undefined behavior from safe code
`FormatContext` stream accessors can cause undefined behavior from safe code
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)
SurrealDB server-takeover via SurrealQL injection on backup import
SurrealDB server-takeover via SurrealQL injection on backup import
crossbeam-channel Vulnerable to Double Free on Drop
crossbeam-channel Vulnerable to Double Free on Drop
Tokio broadcast channel calls clone in parallel, but does not require `Sync`
Tokio broadcast channel calls clone in parallel, but does not require `Sync`
gitoxide does not detect SHA-1 collision attacks
gitoxide does not detect SHA-1 collision attacks
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
Improper Scope Validation in the `open` Endpoint of `tauri-plugin-shell`
PyO3 Risk of buffer overflow in `PyString::from_object`
PyO3 Risk of buffer overflow in `PyString::from_object`
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
xmas-elf: before 0.10
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write
Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write
Crash due to uncontrolled recursion in protobuf crate
Crash due to uncontrolled recursion in protobuf crate
Some AES functions may panic when overflow checking is enabled in ring
Some AES functions may panic when overflow checking is enabled in ring
Fyrox has unsound usages of `Vec::from_raw_parts`
Fyrox has unsound usages of `Vec::from_raw_parts`
fyrox-core: 0.28.1 → 0.36
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Hickory DNS failure to verify self-signed RRSIG for DNSKEYs
Hickory DNS's DNSSEC validation may accept broken authentication chains
Hickory DNS's DNSSEC validation may accept broken authentication chains
rust-openssl ssl::select_next_proto use after free
rust-openssl ssl::select_next_proto use after free
fast-fault has a segmentation fault due to lack of bound check
fast-fault has a segmentation fault due to lack of bound check
gix-worktree-state nonexclusive checkout sets executable files world-writable
gix-worktree-state nonexclusive checkout sets executable files world-writable
rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
`idna` accepts Punycode labels that do not produce any non-ASCII when decoded
Unsound usages of `std::slice::from_raw_parts`
Unsound usages of `std::slice::from_raw_parts`
Borsh serialization of HashMap is non-canonical
Borsh serialization of HashMap is non-canonical
Unsoundness in anstream
Unsoundness in anstream
`ruzstd` uninit and out-of-bounds memory reads
`ruzstd` uninit and out-of-bounds memory reads
rustls network-reachable panic in `Acceptor::accept`
rustls network-reachable panic in `Acceptor::accept`
`parse_arguments` reads a caller-supplied pointer as a slice
`parse_arguments` reads a caller-supplied pointer as a slice
SurrealDB has an Uncaught Exception Handling Nonexistent Role
SurrealDB has an Uncaught Exception Handling Nonexistent Role
s2n-tls has undefined behavior at process exit
s2n-tls has undefined behavior at process exit
`fast-float` has multiple soundness issues
`fast-float` has multiple soundness issues
Mimalloc Can Allocate Memory with Bad Alignment
Mimalloc Can Allocate Memory with Bad Alignment
cap-std doesn't fully sandbox all the Windows device filenames
cap-std doesn't fully sandbox all the Windows device filenames
Wasmtime doesn't fully sandbox all the Windows device filenames
Wasmtime doesn't fully sandbox all the Windows device filenames
Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations
Wasmtime race condition could lead to WebAssembly control-flow integrity and type safety violations
wasmtime has a runtime crash when combining tail calls with trapping imports
wasmtime has a runtime crash when combining tail calls with trapping imports
SurrealDB: Improper Authorization in Select Permissions
SurrealDB: Improper Authorization in Select Permissions
Tonic has remotely exploitable denial of service vulnerability
Tonic has remotely exploitable denial of service vulnerability
lexical-core has multiple soundness issues
lexical-core has multiple soundness issues
gix-path improperly resolves configuration path reported by Git
gix-path improperly resolves configuration path reported by Git
gix-path uses local config across repos when it is the highest scope
gix-path uses local config across repos when it is the highest scope
Denial of service in quinn-proto when using `Endpoint::retry()`
Denial of service in quinn-proto when using `Endpoint::retry()`
SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
boa_engine: 0.16 → 0.19.0
s2n-tls's mTLS API ordering may skip client authentication
s2n-tls's mTLS API ordering may skip client authentication
The kstring integration in gix-attributes is unsound
The kstring integration in gix-attributes is unsound
Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
openssl's `MemBio::get_buf` has undefined behavior with empty buffers
gix-path can use a fake program files location
gix-path can use a fake program files location
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key material
vodozemac's usage of non-constant time base64 decoder could lead to leakage of secret key material
panic on parsing crafted phonenumber inputs
panic on parsing crafted phonenumber inputs
zerovec incorrectly uses `#[repr(packed)]`
zerovec incorrectly uses `#[repr(packed)]`
zerovec-derive incorrectly uses `#[repr(packed)]`
zerovec-derive incorrectly uses `#[repr(packed)]`
Unlimited number of NTS-KE connections can crash ntpd-rs server
Unlimited number of NTS-KE connections can crash ntpd-rs server
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`
Symlink bypasses filesystem sandbox
Symlink bypasses filesystem sandbox
s2n-tls has a potentially observable differences in RSA premaster secret handling
s2n-tls has a potentially observable differences in RSA premaster secret handling
Unable to generate the correct character set
Unable to generate the correct character set
gix refs and paths with reserved Windows device names access the devices
gix refs and paths with reserved Windows device names access the devices
gix traversal outside working tree enables arbitrary code execution
gix traversal outside working tree enables arbitrary code execution
matrix-sdk-crypto contains a log exposure of private key of the server-side key backup
matrix-sdk-crypto contains a log exposure of private key of the server-side key backup
Spin applications with specific configuration vulnerable to potential network sandbox escape
Spin applications with specific configuration vulnerable to potential network sandbox escape
Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag
Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag
vodozemac has degraded secret zeroization capabilities
vodozemac has degraded secret zeroization capabilities
Apollo Router vulnerable to Critical Regression In Query Plan Cache
Apollo Router vulnerable to Critical Regression In Query Plan Cache
Yamux Memory Exhaustion Vulnerability via Active::pending_frames property
Yamux Memory Exhaustion Vulnerability via Active::pending_frames property
Denial of Service Vulnerability in Rustls Library
Denial of Service Vulnerability in Rustls Library
gix-transport indirect code execution via malicious username
gix-transport indirect code execution via malicious username
gix: before 0.62
eyre: Parts of Report are dropped as the wrong type during downcast
eyre: Parts of Report are dropped as the wrong type during downcast
h2 servers vulnerable to degradation of service with CONTINUATION Flood
h2 servers vulnerable to degradation of service with CONTINUATION Flood
cassandra-rs's non-idiomatic use of iterators leads to use after free
cassandra-rs's non-idiomatic use of iterators leads to use after free
Wasmtime vulnerable to panic when using a dropped extenref-typed element segment
Wasmtime vulnerable to panic when using a dropped extenref-typed element segment
tls-listener affected by the slow loris vulnerability with default configuration
tls-listener affected by the slow loris vulnerability with default configuration
Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters
Wasmi Out-of-bounds Write for host to Wasm calls with more than 128 Parameters
Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass
Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass
Deno's improper suffix match testing for DENO_AUTH_TOKENS
Deno's improper suffix match testing for DENO_AUTH_TOKENS
Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping
Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping
Insufficient permission checking in `Deno.makeTemp*` APIs
Insufficient permission checking in `Deno.makeTemp*` APIs
Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
Mio's tokens for named pipes may be delivered after deregistration
Mio's tokens for named pipes may be delivered after deregistration
libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2
libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2
Any authenticated user may obtain private message details from other users on the same instance
Any authenticated user may obtain private message details from other users on the same instance
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in trillium-http and trillium-client
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in trillium-http and trillium-client
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)
Uncaught Exception processing HTTP Headers in SurrealDB
Uncaught Exception processing HTTP Headers in SurrealDB
Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders
Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
Rust EVM erroneousle handles `record_external_operation` error return
Rust EVM erroneousle handles `record_external_operation` error return
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platforms
unsafe-libyaml unaligned write of u64 on 32-bit and 16-bit platforms
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
paramiko: 2.5.0 → 3.4.0
SurrealDB: Full Table Permissions by Default
SurrealDB: Full Table Permissions by Default
Wasmer filesystem sandbox not enforced
Wasmer filesystem sandbox not enforced
Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
Marvin Attack: potential key recovery through timing sidechannels
`openssl` `X509StoreRef::objects` is unsound
`openssl` `X509StoreRef::objects` is unsound
stellar-strkey vulnerable to panic in SignedPayload::from_payload
stellar-strkey vulnerable to panic in SignedPayload::from_payload
Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables
Tauri's Updater Private Keys Possibly Leaked via Vite Environment Variables
Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions
Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions
rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
rustix's `rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosion
Tungstenite allows remote attackers to cause a denial of service
Tungstenite allows remote attackers to cause a denial of service
Denial of Service issue in quinn-proto
Denial of Service issue in quinn-proto
SQLpage vulnerable to public exposure of database credentials
SQLpage vulnerable to public exposure of database credentials
libwebp: OOB write in BuildHuffmanTable
libwebp: OOB write in BuildHuffmanTable
SkiaSharp: 2.0.0 → 2.88.6
Users vulnerable to unaligned read of `*const *const c_char` pointer
Users vulnerable to unaligned read of `*const *const c_char` pointer
Apollo Router Unnamed "Subscription" operation results in Denial-of-Service
Apollo Router Unnamed "Subscription" operation results in Denial-of-Service
Default functions in VolatileMemory trait lack bounds checks, potentially leading to out-of-bounds memory accesses
Default functions in VolatileMemory trait lack bounds checks, potentially leading to out-of-bounds memory accesses
webpki: CPU denial of service in certificate path building
webpki: CPU denial of service in certificate path building
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
cargo: 1.60.0 → 1.72
rustls-webpki: CPU denial of service in certificate path building
rustls-webpki: CPU denial of service in certificate path building
zola Path Traversal vulnerability
zola Path Traversal vulnerability
twitch-tui's connection is not encrypted
twitch-tui's connection is not encrypted
atty potential unaligned read
atty potential unaligned read
`openssl` `X509VerifyParamRef::set_host` buffer over-read
`openssl` `X509VerifyParamRef::set_host` buffer over-read
Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles
Tauri vulnerable to Regression on Filesystem Scope Checks for Dotfiles
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
Missing "--allow-net" permission check for built-in Node modules
Missing "--allow-net" permission check for built-in Node modules
Improper handling of NTS cookie length that could crash the ntpd-rs server
Improper handling of NTS cookie length that could crash the ntpd-rs server
Tauri Open Redirect Vulnerability Possibly Exposes IPC to External Sites
Tauri Open Redirect Vulnerability Possibly Exposes IPC to External Sites
spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers
spin-rs initialisation failure in `Once::try_call_once` can lead to undefined behaviour for other initialisers
Comrak AST node data is not validated (GHSL-2023-049)
Comrak AST node data is not validated (GHSL-2023-049)
Interactive `run` permission prompt spoofing via improper ANSI neutralization
Interactive `run` permission prompt spoofing via improper ANSI neutralization
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64
wasmtime vulnerable to guest-controlled out-of-bounds read/write on x86_64
wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64
wasmtime vulnerable to miscompilation of `i8x16.select` with the same inputs on x86_64
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`
openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
openssl-src contains `NULL` dereference during PKCS7 data verification
openssl-src contains `NULL` dereference during PKCS7 data verification
openssl-src subject to NULL dereference validating DSA public key
openssl-src subject to NULL dereference validating DSA public key
openssl-src contains Double free after calling `PEM_read_bio_ex`
openssl-src contains Double free after calling `PEM_read_bio_ex`
openssl-src subject to Timing Oracle in RSA Decryption
openssl-src subject to Timing Oracle in RSA Decryption
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions
openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions
`tokio::io::ReadHalf<T>::unsplit` is Unsound
`tokio::io::ReadHalf<T>::unsplit` is Unsound
Aliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`
bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`
Deno is vulnerable to race condition via interactive permission prompt spoofing
Deno is vulnerable to race condition via interactive permission prompt spoofing
Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe
Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe
Denial of service by double-checked locking in openssl-src
Denial of service by double-checked locking in openssl-src
X.509 Email Address 4-byte Buffer Overflow
X.509 Email Address 4-byte Buffer Overflow
X.509 Email Address Variable Length Buffer Overflow
X.509 Email Address Variable Length Buffer Overflow
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
traitobject is Unmaintained
traitobject is Unmaintained
typemap is Unmaintained
typemap is Unmaintained
AES OCB fails to encrypt some bytes
AES OCB fails to encrypt some bytes
Out-of-bounds write in nix::unistd::getgrouplist
Out-of-bounds write in nix::unistd::getgrouplist
Parser creates invalid uninitialized value
Parser creates invalid uninitialized value
Cargo prior to Rust 1.26.0 may download the wrong dependency
Cargo prior to Rust 1.26.0 may download the wrong dependency
Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
Microsoft.NETCore.App.Runtime.linux-arm: 3.0.0 → 3.1.23
Resource leakage when decoding certificates and keys
Resource leakage when decoding certificates and keys
Incorrect MAC key used in the RC4-MD5 ciphersuite
Incorrect MAC key used in the RC4-MD5 ciphersuite
`OCSP_basic_verify` may incorrectly verify the response signing certificate
`OCSP_basic_verify` may incorrectly verify the response signing certificate
openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates
Out-of-bounds Write in nix
Out-of-bounds Write in nix
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
coreos-installer improperly verifies GPG signature when decompressing gzipped artifact
Async-h1 request smuggling possible with long unread bodies
Async-h1 request smuggling possible with long unread bodies
Out of bounds write in traitobject
Out of bounds write in traitobject
Double free in http
Double free in http
Incorrect cast in anymap
Incorrect cast in anymap
Segmentation fault in time
Segmentation fault in time
Null pointer deference in openssl-src
Null pointer deference in openssl-src
Integer Overflow/Infinite Loop in the http crate
Integer Overflow/Infinite Loop in the http crate
Free of uninitialized memory in telemetry
Free of uninitialized memory in telemetry
XSS in mdBook
XSS in mdBook
Integer Overflow in Chunked Transfer-Encoding
Integer Overflow in Chunked Transfer-Encoding
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
Lenient Parsing of Content-Length Header When Prefixed with Plus Sign
Triton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
Tooling for crates.io
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.