Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2jx3-ff3v-j7jj
  • crates.io/yara-x
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB 3 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
RUSTSEC-2026-0308
  • crates.io/salsa
Use-after-free in interned values and cached function results 11 hours ago
  • Fix available
RUSTSEC-2026-0305
  • crates.io/librsvg
Use-after-free when XML includes have duplicated entities yesterday
  • Fix available
RUSTSEC-2026-0307
  • crates.io/uncbv
`uncbv`: archive extraction is vulnerable to path traversal (zip-slip) yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-m8f5-rh7h-vgg3
  • crates.io/microsandbox
microsandbox: Secret values exposed in world-readable process arguments 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
RUSTSEC-2026-0299
  • crates.io/owned-alloc
`owned-alloc` is unmaintained 2 days ago
  • No fix available
RUSTSEC-2026-0301
  • crates.io/stack_collections
Double free in `StackVec::retain` when a predicate or element `Drop` panics 2 days ago
  • Fix available
RUSTSEC-2026-0302
  • crates.io/stack-graphs
`stack-graphs` C API exports are safe `extern "C"` functions 2 days ago
  • No fix available
RUSTSEC-2026-0303
  • crates.io/stack-graphs
`stack-graphs` is archived and unmaintained 2 days ago
  • No fix available
RUSTSEC-2026-0293
  • crates.io/ringbuf
Double free / use-after-free in `Consumer::skip` and `Consumer::clear` when an element's `Drop` panics 3 days ago
  • Fix available
RUSTSEC-2026-0296
  • crates.io/unzip
`unzip` is unmaintained 3 days ago
  • No fix available
RUSTSEC-2026-0304
  • crates.io/connectrpc
Finished streaming calls keep reading a stalled request body indefinitely 3 days ago
  • Fix available
  • Severity - 6.3 (Medium)
RUSTSEC-2026-0306
  • crates.io/faster-hex
`hex_decode_unchecked` AVX2 path reads past `src` 4 days ago
  • Fix available
RUSTSEC-2026-0294
  • crates.io/iceoryx2-bb-container
Unsoundness in UTF-8 'String' trait 6 days ago
  • Fix available
GHSA-4rf6-qx84-q9fv
  • crates.io/fulgur
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service) 17 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-j5cx-ph8g-95v3
  • crates.io/fulgur
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service 17 Sep
  • Fix available
  • Severity - 7.5 (High)