Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-6g2r-675j-hx59
  • crates.io/xxhash-rust
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release 3 hours ago
  • Fix available
  • Severity - 2.3 (Low)
GHSA-c9xm-49cp-xcr9
  • crates.io/rmcp
rmcp OAuth client fetches server-controlled resource_metadata URLs 6 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
RUSTSEC-2026-0319
  • crates.io/anymap2
anymap2 is unmaintained 10 hours ago
  • No fix available
RUSTSEC-2026-0320
  • crates.io/wasmtime-wasi-http
Wasmtime wasi:http implementation panics with a zero timeout supplied 10 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0321
  • crates.io/wasmtime-wasi
WASI preview 0 implementation of `poll_oneoff` circumvents fuel consumption 10 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
RUSTSEC-2026-0322
  • crates.io/wasmtime-wasi
Excessive allocated memory on the host when guests don't have stdio 10 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0323
  • crates.io/wasmtime-wasi
fd_readdir copies uninitialized struct padding into guest memory 10 hours ago
  • Fix available
  • Severity - 2.1 (Low)
RUSTSEC-2026-0324
  • crates.io/wasmtime-wasi
Guest can panic host through filesystem timestamp before the epoch on wasip3 10 hours ago
  • Fix available
  • Severity - 6.2 (Medium)
RUSTSEC-2026-0325
  • crates.io/wasmtime
Mis-typed WebAssembly tag imports can lead to GC heap corruption 10 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
RUSTSEC-2026-0326
  • crates.io/wasmtime
Rooting for GC values live across `try_call` may be missing, causing GC heap corruption 10 hours ago
  • Fix available
  • Severity - 5.7 (Medium)
RUSTSEC-2026-0327
  • crates.io/wasmtime
Wasmtime component async-lifted callback result count is unvalidated, causing a native stack buffer overflow 10 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-g4mp-vgx3-xrvm
  • crates.io/pageant
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows) yesterday
  • Fix available
  • Severity - 6.2 (Medium)
GHSA-35g8-35p8-c8fw
  • crates.io/russh
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-p8qx-h547-fjw9
  • crates.io/russh
russh: negotiating a MAC-requiring block cipher (CTR/CBC) with mac=none causes a slice-index-out-of-range panic yesterday
  • Fix available
  • Severity - 3.7 (Low)
GHSA-47hw-gvq5-r2gm
  • crates.io/russh
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-w3jg-pjxf-73p4
  • crates.io/russh
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange yesterday
  • Fix available
  • Severity - 4.3 (Medium)