RUSTSEC-2026-0175

Source
https://rustsec.org/advisories/RUSTSEC-2026-0175
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0175.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0175
Published
2026-06-10T12:00:00Z
Modified
2026-06-10T19:15:05.267059444Z
Summary
`onering` 1.4.1 was removed from crates.io for malicious code
Details

A new version of the onering crate was published with code that attempted to exfiltrate both metadata and code from the project it was included within.

One malicious version was published on 2026-06-10, approximately six hours before removal. This crate has no dependencies on crates.io, and there is no evidence of actual usage of the compromised version.

Thanks to Charlie Eriksen for the report.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / onering

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.4.1
Fixed
1.4.2-0

Ecosystem specific

{
    "affects": {
        "functions": [],
        "arch": [],
        "os": []
    },
    "affected_functions": null
}

Database specific

categories
[
    "malicious"
]
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0175.json"
cvss
null
informational
null