Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
RUSTSEC-2026-0311
  • crates.io/latex-rust
Stack overflow on deeply nested LaTeX input 2 days ago
  • Fix available
RUSTSEC-2026-0310
  • crates.io/domain
Various panics, soundness and resource exhaustion issues 4 days ago
  • Fix available
GHSA-2jx3-ff3v-j7jj
  • crates.io/yara-x
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB 5 days ago
  • Fix available
  • Severity - 4.8 (Medium)
RUSTSEC-2026-0308
  • crates.io/salsa
Use-after-free in interned values and cached function results 5 days ago
  • Fix available
RUSTSEC-2026-0312
  • crates.io/x509-validator
Excluded iPAddress name constraints with an all-zero mask are not applied 5 days ago
  • Fix available
  • Severity - 7.4 (High)
RUSTSEC-2026-0313
  • crates.io/wasmtime-wasi-http
Outgoing HTTP body write allows guest-driven host memory exhaustion 5 days ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0314
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem datetime overflow 5 days ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0315
  • crates.io/wasmtime
`call_ref` and exception `catch` can drop some fuel accounting, leading to exponential fuel amplification 5 days ago
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0316
  • crates.io/wasmtime
Dynamic record lifting can allocate beyond the hostcall fuel limit 5 days ago
  • Fix available
  • Severity - 1.0 (Low)
RUSTSEC-2026-0305
  • crates.io/librsvg
Use-after-free when XML includes have duplicated entities 6 days ago
  • Fix available
RUSTSEC-2026-0307
  • crates.io/uncbv
`uncbv`: archive extraction is vulnerable to path traversal (zip-slip) 6 days ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-m8f5-rh7h-vgg3
  • crates.io/microsandbox
microsandbox: Secret values exposed in world-readable process arguments 6 days ago
  • Fix available
  • Severity - 6.5 (Medium)
RUSTSEC-2026-0299
  • crates.io/owned-alloc
`owned-alloc` is unmaintained 22 Sep
  • No fix available
RUSTSEC-2026-0301
  • crates.io/stack_collections
Double free in `StackVec::retain` when a predicate or element `Drop` panics 22 Sep
  • Fix available
RUSTSEC-2026-0302
  • crates.io/stack-graphs
`stack-graphs` C API exports are safe `extern "C"` functions 22 Sep
  • No fix available
RUSTSEC-2026-0303
  • crates.io/stack-graphs
`stack-graphs` is archived and unmaintained 22 Sep
  • No fix available