Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-cjcg-cxmh-9wcr
  • crates.io/praxis-proxy
Praxis affected by HTTP/2 Bomb yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-2hw9-mc66-jc2q
  • crates.io/wasmtime
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state yesterday
  • Fix available
  • Severity - 2.0 (Low)
GHSA-8ffr-xgwf-xj56
  • crates.io/aws-smithy-json
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers yesterday
  • Fix available
  • Severity - 8.7 (High)
GHSA-6g2r-675j-hx59
  • crates.io/xxhash-rust
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release yesterday
  • Fix available
  • Severity - 2.3 (Low)
GHSA-c9xm-49cp-xcr9
  • crates.io/rmcp
rmcp OAuth client fetches server-controlled resource_metadata URLs yesterday
  • Fix available
  • Severity - 6.3 (Medium)
RUSTSEC-2026-0319
  • crates.io/anymap2
anymap2 is unmaintained 2 days ago
  • No fix available
RUSTSEC-2026-0320
  • crates.io/wasmtime-wasi-http
Wasmtime wasi:http implementation panics with a zero timeout supplied 2 days ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0321
  • crates.io/wasmtime-wasi
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption 2 days ago
  • Fix available
  • Severity - 4.0 (Medium)
RUSTSEC-2026-0322
  • crates.io/wasmtime-wasi
Excessive allocated memory on the host when guests don't have stdio 2 days ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0323
  • crates.io/wasmtime-wasi
fd_readdir copies uninitialized struct padding into guest memory 2 days ago
  • Fix available
  • Severity - 2.1 (Low)
RUSTSEC-2026-0324
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem timestamp before the epoch on wasip3 2 days ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0325
  • crates.io/wasmtime
Mis-typed WebAssembly tag imports can lead to GC heap corruption 2 days ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0326
  • crates.io/wasmtime
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption 2 days ago
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0327
  • crates.io/wasmtime
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow 2 days ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-g4mp-vgx3-xrvm
  • crates.io/pageant
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) 3 days ago
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-35g8-35p8-c8fw
  • crates.io/russh
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey 3 days ago
  • Fix available
  • Severity - 6.5 (Medium)