crates.io incidents
Recent crates.io vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free)
`tinymember` was removed from crates.io due to affiliation with malicious code
`tinymember` was removed from crates.io due to affiliation with malicious code
Malicious code in internment (crates.io)
Malicious code in internment (crates.io)
Malicious code in tinymember (crates.io)
Malicious code in tinymember (crates.io)
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
`arrayref` 0.3.10 was removed from crates.io due to a malicious dependency
Malicious code in arrayref (crates.io)
Malicious code in arrayref (crates.io)
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
`append-only-vec` 0.1.9 was removed from crates.io due to a malicious dependency
Malicious code in append_only_vec (crates.io)
Malicious code in append_only_vec (crates.io)
`arone` was removed from crates.io due to malicious code
`arone` was removed from crates.io due to malicious code
Malicious code in proc_macro1 (crates.io)
Malicious code in proc_macro1 (crates.io)
Malicious code in aronenao (crates.io)
Malicious code in aronenao (crates.io)
`aronenao` was removed from crates.io due to malicious code
`aronenao` was removed from crates.io due to malicious code
`proc-macro1` was removed from crates.io due to malicious code
`proc-macro1` was removed from crates.io due to malicious code
Malicious code in proc_macro_en (crates.io)
Malicious code in proc_macro_en (crates.io)
`proc-macro-en` was removed from crates.io due to malicious code
`proc-macro-en` was removed from crates.io due to malicious code
Malicious code in arone (crates.io)
Malicious code in arone (crates.io)
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
`internment` 0.8.7 was removed from crates.io due to a malicious dependency
Malicious code in aovine (crates.io)
Malicious code in aovine (crates.io)
block_buffer: panic corrupts inline buffer position
block_buffer: panic corrupts inline buffer position
Triton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
h2 unbounded empty DATA frames
h2 unbounded empty DATA frames
s2n-quic has excessive memory allocation
s2n-quic has excessive memory allocation
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
nimiq-blockchain: Validity store off by one error
nimiq-blockchain: Validity store off by one error
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk` and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
Panic-safety unsoundness in `truncate_back`, `truncate_front`, `clear`, and `extend_from_slice` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Panic-safety unsoundness in `Chunk`, `RingBuffer`, and `InlineArray` (use-after-free / double-free)
Ed25519 identity public keys permit universal signature forgery
Ed25519 identity public keys permit universal signature forgery
Low-level GCM ignores the operation nonce
Low-level GCM ignores the operation nonce
Streaming AEAD does not authenticate stream structure
Streaming AEAD does not authenticate stream structure
Safe ErrorRegistry APIs can cause undefined behavior
Safe ErrorRegistry APIs can cause undefined behavior
`sevenz-rust` is unmaintained
`sevenz-rust` is unmaintained
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
A `BigInt` division panics, and two neighbouring operations answer wrongly in silence
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
`setlocale` and `TextDomain::init` are unsound as they access environment with no synchronization
`nostr-relay-builder` is unmaintained
`nostr-relay-builder` is unmaintained
Russh: Channel-scoped server callbacks can be reached without an open channel
Russh: Channel-scoped server callbacks can be reached without an open channel
`nostr-relay-pool` is unmaintained
`nostr-relay-pool` is unmaintained
`nostr-keyring` is unmaintained
`nostr-keyring` is unmaintained
Processing of unverified relay events
Processing of unverified relay events
NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
Relay authentication challenges can exhaust memory
Relay authentication challenges can exhaust memory
NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
Verification cache poisoning allows forged Nostr events to bypass signature validation
Verification cache poisoning allows forged Nostr events to bypass signature validation
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
Stores can mix up type indices between engines
Stores can mix up type indices between engines
Preemption and traps during bulk operations enable breaking internal VM state
Preemption and traps during bulk operations enable breaking internal VM state
Unix `BROWSER` handling allows browser argument injection
Unix `BROWSER` handling allows browser argument injection
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
`event-listener` allows `!Send` tags to cross thread boundaries via `StackSlot`
Uint shift operations: incorrect overflow flags and truncated shift amounts
Uint shift operations: incorrect overflow flags and truncated shift amounts
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Panic on a `DataRow` with fewer fields than columns allows denial of service
Panic on a `DataRow` with fewer fields than columns allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
Panic decoding a malformed `hstore` value allows denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
Use-after-free
Use-after-free
TLS hostname verification disabled when using Boring TLS backend
TLS hostname verification disabled when using Boring TLS backend
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Insufficient archive validation can cause out-of-bounds reads in archives containing Rc/Arc
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
Potential use-after-free due to lack of panic safety in `LruCache::pop()`
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Insufficient archive validation can cause out-of-bounds reads in archives containing hash tables
Crafted archives can cause a use-after-free during deserialization
Crafted archives can cause a use-after-free during deserialization
ldap3_proto has LDAP Filter stack exhaustion
ldap3_proto has LDAP Filter stack exhaustion
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
smartstring is unmaintained
smartstring is unmaintained
bitmaps is unmaintained
bitmaps is unmaintained
sized-chunks is unmaintained
sized-chunks is unmaintained
im-rc is unmaintained
im-rc is unmaintained
im is unmaintained
im is unmaintained
actix-http has HTTP/1.1 CL.TE Request Smuggling
actix-http has HTTP/1.1 CL.TE Request Smuggling
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Bug-Fixes in `libcrux-ecdh`, `libcrux-ed25519`, `libcrux-psq`
Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext
Panic in `libcrux-psq` on decryption of malformed AES-GCM ciphertext
[actix-files] Panic triggered by empty Range header in GET request for static file
[actix-files] Panic triggered by empty Range header in GET request for static file
actix-files has a possible exposure of information vulnerability
actix-files has a possible exposure of information vulnerability
Unnecessary clamping of seed reduces seed entropy to 251 bits
Unnecessary clamping of seed reduces seed entropy to 251 bits
X25519 secret validation did not check buffer length or clamping
X25519 secret validation did not check buffer length or clamping
Incorrect X25519 clamping check rejects all secrets on import
Incorrect X25519 clamping check rejects all secrets on import
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
RustCrypto Utilities cmov: `thumbv6m-none-eabi` compiler emits non-constant time assembly when using `cmovnz`
`Bitmap::try_from(&[u8])` can create invalid values
`Bitmap::try_from(&[u8])` can create invalid values
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
`hugepage_rs::dealloc` may allow invalid memory deallocation from safe code
`FormatContext` stream accessors can cause undefined behavior from safe code
`FormatContext` stream accessors can cause undefined behavior from safe code
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
zip Incorrectly Canonicalizes Paths during Archive Extraction Leading to Arbitrary File Write
Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write
Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write
Some AES functions may panic when overflow checking is enabled in ring
Some AES functions may panic when overflow checking is enabled in ring
tls-listener affected by the slow loris vulnerability with default configuration
tls-listener affected by the slow loris vulnerability with default configuration
Full Table Permissions by Default
Full Table Permissions by Default
Aliasing violation in `OrdSet` insertion
Aliasing violation in `OrdSet` insertion
Triton VM Soundness Vulnerability due to Missing Constraint
Triton VM Soundness Vulnerability due to Missing Constraint
Tooling for crates.io
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.