Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-7w2g-9mf9-324m
  • crates.io/hurl
Hurl: Cookies in Cookies section leak when redirecting to a different host yesterday
  • No fix available
  • Severity - 6.9 (Medium)
RUSTSEC-2026-0278
  • crates.io/zbus_polkit
`zbus_polkit`: authorization bypass via PID reuse 3 days ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-f9qc-qg88-7pq5
  • crates.io/buffa
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation 6 days ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-9pwq-gcrx-wghh
  • crates.io/buffa
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-gpwf-4h98-v82q
  • crates.io/datadog-opentelemetry
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-2vh6-hw4j-32ww
  • crates.io/gix-packetline
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS) 6 days ago
  • Fix available
  • Severity - 6.5 (Medium)
RUSTSEC-2026-0272
  • crates.io/stack_dst
Panic-safety unsoundness in `Stack::pop`, `Fifo::pop_front` and `Value::replace_stable` (use-after-free / double-free) 27 Aug
  • Fix available
GHSA-3p27-qvp9-27qf
  • crates.io/wasmtime-wasi
Wasmtime has a leak in WASIp1 `fd_renumber` implementation 26 Aug
  • Fix available
  • Severity - 2.3 (Low)
RUSTSEC-2026-0276
  • crates.io/apimock
Path traversal in apimock's file-serving fallback 26 Aug
  • Fix available
  • Severity - 8.2 (High)
RUSTSEC-2026-0277
  • crates.io/apimock-server
Path traversal in apimock-server's file-serving fallback 26 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-p7x2-g5cq-fhmq
  • crates.io/mediasoup
  • npm/mediasoup
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation) 25 Aug
  • Fix available
  • Severity - 5.6 (Medium)
GHSA-fx4f-mhw4-qm7j
  • crates.io/vibeio-http
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths 24 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-3gjw-f78c-vvpw
  • crates.io/tokio-postgres
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service 24 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-rgqc-3x5p-6gwg
  • crates.io/postgres-protocol
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service 24 Aug
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-5x78-73v4-xg6w
  • crates.io/postgres-protocol
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service 24 Aug
  • Fix available
  • Severity - 8.7 (High)
RUSTSEC-2026-0267
  • crates.io/stable-vec
Panic-safety unsoundness in `BitVecCore::clear` (double-free / use-after-free) 24 Aug
  • Fix available