Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g4mp-vgx3-xrvm
  • crates.io/pageant
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) 21 hours ago
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-35g8-35p8-c8fw
  • crates.io/russh
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey 21 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-p8qx-h547-fjw9
  • crates.io/russh
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic 21 hours ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-47hw-gvq5-r2gm
  • crates.io/russh
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened 21 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-w3jg-pjxf-73p4
  • crates.io/russh
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange 21 hours ago
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-g6xm-f9xp-qq35
  • crates.io/russh
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path 21 hours ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-m6mh-2hw2-555x
  • crates.io/ammonia
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') yesterday
  • Fix available
  • Severity - 5.4 (Medium)
RUSTSEC-2026-0317
  • crates.io/sheets-diff
A 512-byte workbook can provoke a multi-gigabyte allocation and abort the process 2 days ago
  • Fix available
  • Severity - 5.5 (Medium)
RUSTSEC-2026-0318
  • crates.io/matrix-sdk-crypto
Sending custom to-device messages may panics 2 days ago
  • Fix available
RUSTSEC-2026-0311
  • crates.io/latex-rust
Stack overflow on deeply nested LaTeX input 4 days ago
  • Fix available
RUSTSEC-2026-0310
  • crates.io/domain
Various panics, soundness and resource exhaustion issues 6 days ago
  • Fix available
GHSA-2jx3-ff3v-j7jj
  • crates.io/yara-x
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB 24 Sep
  • Fix available
  • Severity - 4.8 (Medium)
RUSTSEC-2026-0308
  • crates.io/salsa
Use-after-free in interned values and cached function results 24 Sep
  • Fix available
RUSTSEC-2026-0312
  • crates.io/x509-validator
Excluded iPAddress name constraints with an all-zero mask are not applied 24 Sep
  • Fix available
  • Severity - 7.4 (High)
RUSTSEC-2026-0313
  • crates.io/wasmtime-wasi-http
Outgoing HTTP body write allows guest-driven host memory exhaustion 24 Sep
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0314
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem datetime overflow 24 Sep
  • Fix available
  • Severity - 6.2 (Medium)